CVE-2019-5418
Rails Ruby on Rails Path Traversal Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 July 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 98.51% probability · 100th percentile
- CISA KEV
- Listed 7 July 2025 · due 28 July 2025
- Weakness
- CWE-22
- Affected
- rubyonrails/rails · debian/debian linux · redhat/cloudforms · opensuse/leap · fedoraproject/fedora · redhat/software collections
- Source
- support@hackerone.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-5418
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152178/Rails-5.2.1-Arbitrary-File-Content-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/03/22/1Mailing List, Mitigation, Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1147Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1149Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1289Third Party Advisory
- https://groups.google.com/forum/#%21topic/rubyonrails-security/pFRKI96Sm8QPermissions Required
- https://lists.debian.org/debian-lts-announce/2019/03/msg00042.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/Third Party Advisory
- https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/Broken Link, Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/46585/Exploit, Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152178/Rails-5.2.1-Arbitrary-File-Content-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/03/22/1Mailing List, Mitigation, Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1147Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1149Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1289Third Party Advisory
- https://groups.google.com/forum/#%21topic/rubyonrails-security/pFRKI96Sm8QPermissions Required
- https://lists.debian.org/debian-lts-announce/2019/03/msg00042.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/Third Party Advisory
- https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/Broken Link, Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/46585/Exploit, Third Party Advisory, VDB Entry
- https://web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-5418US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.