Back

HIGH KEV

rubygem-actionpack: render file directory traversal in Action View

Published Mar 27, 2019 ·Due Jul 28, 2025

Description

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

Affected products

Remediation

Red Hat statement

This issue did affect the versions of rh-ror42-rubygem-actionpack and rh-ror50-rubygem-actionpack as shipped with Red Hat Software Collections.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Mar 27, 2019
Updated Oct 21, 2025
Reserved Jan 4, 2019
CISA Vulnrichment
Updated Jul 17, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 13, 2019
GHSA-86G5-2WH3-GC9J