There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rails | Apr 1, 2019 | Mar 27, 2019 |
| Freebsd | — | Upgrade rubygem-actionview4Upgrade rubygem-actionview5Upgrade rubygem-actionview50 | Mar 19, 2019 | Mar 18, 2019 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Jan 3, 2020 | Mar 27, 2019 |
| Suse | — | Upgrade rmt-server-pubcloudUpgrade rmt-serverUpgrade ruby2.5-rubygem-actionpack-5_1Upgrade ruby2.5-rubygem-actionpack-doc-5_1Upgrade rmt-server-config | May 9, 2019 | Mar 13, 2019 |
| Ubuntu | — | Upgrade ruby-actionpack (Ubuntu Pro)Upgrade ruby-actionview (Ubuntu Pro)Upgrade rails (Ubuntu Pro) | Jun 26, 2025 | Mar 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub