← Back to browse · API

CVE-2019-5418

Severity
HIGH
CVSS
7.5
EPSS
0.98507
Risk score
59.48
CISA KEV
Yes
PoC
No
Published
2019-03-27
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-0375, GHSA-86G5-2WH3-GC9J
Products
Rails:Ruby on Rails, rails:https://github.com/rails/rails 4.2.11.1, rails:https://github.com/rails/rails 5.0.7.2, rails:https://github.com/rails/rails 5.1.6.2, rails:https://github.com/rails/rails 5.2.2.1
Sources
cisa.gov CVE-2019-5418
euvd EUVD-2019-0375

Description

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

References