rubygem-actionpack: denial of service vulnerability in Action View
Published Mar 27, 2019
7.5
HIGHCVSS 3.1
EPSS 8.78%
Description
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
Affected products
-
- Version 4.2.11.1StatusaffectedConstraints-
- Version 5.0.7.2StatusaffectedConstraints-
- Version 5.1.6.2StatusaffectedConstraints-
- Version 5.2.2.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rails | n/a | n/a |
|
Configuration 1
- < 4.2.11.1
- ≥ 5.0.0 · < 5.0.7.2
- ≥ 5.1.0 · < 5.1.6.2
- ≥ 5.2.0 · < 5.2.2.1
Configuration 2
- 8.0
Configuration 3
- 4.6
- 4.7
- 1.0
Configuration 5
- 30
No data.
CloudForms Management Engine 5.10
ansible-tower-0:3.4.3-1.el7at
Fixed · RHSA-2019:0796
CloudForms Management Engine 5.10
cfme-0:5.10.3.3-1.el7cf
Fixed · RHSA-2019:0796
CloudForms Management Engine 5.10
cfme-amazon-smartstate-0:5.10.3.3-1.el7cf
Fixed · RHSA-2019:0796
CloudForms Management Engine 5.10
cfme-appliance-0:5.10.3.3-1.el7cf
Fixed · RHSA-2019:0796
CloudForms Management Engine 5.10
cfme-gemset-0:5.10.3.3-1.el7cf
Fixed · RHSA-2019:0796
CloudForms Management Engine 5.9
cfme-0:5.9.9.3-1.el7cf
Fixed · RHSA-2019:1289
CloudForms Management Engine 5.9
cfme-amazon-smartstate-0:5.9.9.3-1.el7cf
Fixed · RHSA-2019:1289
CloudForms Management Engine 5.9
cfme-appliance-0:5.9.9.3-1.el7cf
Fixed · RHSA-2019:1289
CloudForms Management Engine 5.9
cfme-gemset-0:5.9.9.3-1.el7cf
Fixed · RHSA-2019:1289
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-ror42-rubygem-actionpack-1:4.2.6-5.el6
Fixed · RHSA-2019:1149
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-ror50-rubygem-actionpack-1:5.0.1-2.el6
Fixed · RHSA-2019:1147
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
Fixed · RHSA-2019:1149
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
Fixed · RHSA-2019:1147
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
Fixed · RHSA-2019:1149
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
Fixed · RHSA-2019:1147
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
Fixed · RHSA-2019:1149
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
Fixed · RHSA-2019:1147
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
Fixed · RHSA-2019:1149
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
Fixed · RHSA-2019:1147
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5.10 | ansible-tower-0:3.4.3-1.el7at | Fixed | RHSA-2019:0796 |
| CloudForms Management Engine 5.10 | cfme-0:5.10.3.3-1.el7cf | Fixed | RHSA-2019:0796 |
| CloudForms Management Engine 5.10 | cfme-amazon-smartstate-0:5.10.3.3-1.el7cf | Fixed | RHSA-2019:0796 |
| CloudForms Management Engine 5.10 | cfme-appliance-0:5.10.3.3-1.el7cf | Fixed | RHSA-2019:0796 |
| CloudForms Management Engine 5.10 | cfme-gemset-0:5.10.3.3-1.el7cf | Fixed | RHSA-2019:0796 |
| CloudForms Management Engine 5.9 | cfme-0:5.9.9.3-1.el7cf | Fixed | RHSA-2019:1289 |
| CloudForms Management Engine 5.9 | cfme-amazon-smartstate-0:5.9.9.3-1.el7cf | Fixed | RHSA-2019:1289 |
| CloudForms Management Engine 5.9 | cfme-appliance-0:5.9.9.3-1.el7cf | Fixed | RHSA-2019:1289 |
| CloudForms Management Engine 5.9 | cfme-gemset-0:5.9.9.3-1.el7cf | Fixed | RHSA-2019:1289 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-ror42-rubygem-actionpack-1:4.2.6-5.el6 | Fixed | RHSA-2019:1149 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-ror50-rubygem-actionpack-1:5.0.1-2.el6 | Fixed | RHSA-2019:1147 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ror42-rubygem-actionpack-1:4.2.6-5.el7 | Fixed | RHSA-2019:1149 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ror50-rubygem-actionpack-1:5.0.1-2.el7 | Fixed | RHSA-2019:1147 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-ror42-rubygem-actionpack-1:4.2.6-5.el7 | Fixed | RHSA-2019:1149 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-ror50-rubygem-actionpack-1:5.0.1-2.el7 | Fixed | RHSA-2019:1147 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-ror42-rubygem-actionpack-1:4.2.6-5.el7 | Fixed | RHSA-2019:1149 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-ror50-rubygem-actionpack-1:5.0.1-2.el7 | Fixed | RHSA-2019:1147 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ror42-rubygem-actionpack-1:4.2.6-5.el7 | Fixed | RHSA-2019:1149 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ror50-rubygem-actionpack-1:5.0.1-2.el7 | Fixed | RHSA-2019:1147 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did affect the versions of rh-ror42-rubygem-actionview and rh-ror50-rubygem-actionview as shipped with Red Hat Software Collections.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (43 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 8.78% (0.08778) | 95.03th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.67% (0.08671) | 94.42th | v5 (v2026.06.15) |
| Mar 4, 2026 | 12.12% (0.12118) | 93.66th | v4 (v2025.03.14) |
| Mar 1, 2026 | 4.26% (0.04256) | 88.64th | v4 (v2025.03.14) |
| Feb 4, 2026 | 12.29% (0.12288) | 93.67th | v4 (v2025.03.14) |
| Feb 1, 2026 | 4.32% (0.04323) | 88.67th | v4 (v2025.03.14) |
| Jan 4, 2026 | 12.49% (0.12492) | 93.69th | v4 (v2025.03.14) |
| Jan 1, 2026 | 4.40% (0.04403) | 88.71th | v4 (v2025.03.14) |
| Dec 16, 2025 | 12.49% (0.12492) | 93.67th | v4 (v2025.03.14) |
| Dec 4, 2025 | 9.06% (0.09057) | 92.32th | v4 (v2025.03.14) |
| Dec 1, 2025 | 4.12% (0.04121) | 88.25th | v4 (v2025.03.14) |
| Nov 21, 2025 | 9.06% (0.09057) | 92.31th | v4 (v2025.03.14) |
| Nov 18, 2025 | 13.46% (0.13458) | 93.56th | v4 (v2025.03.14) |
| Nov 4, 2025 | 9.06% (0.09057) | 92.27th | v4 (v2025.03.14) |
| Nov 1, 2025 | 4.12% (0.04121) | 88.17th | v4 (v2025.03.14) |
| Oct 4, 2025 | 9.06% (0.09057) | 92.31th | v4 (v2025.03.14) |
| Oct 1, 2025 | 4.12% (0.04121) | 88.20th | v4 (v2025.03.14) |
| Sep 4, 2025 | 9.06% (0.09057) | 92.34th | v4 (v2025.03.14) |
| Sep 1, 2025 | 4.12% (0.04121) | 88.25th | v4 (v2025.03.14) |
| Aug 4, 2025 | 9.06% (0.09057) | 92.29th | v4 (v2025.03.14) |
| Aug 1, 2025 | 4.12% (0.04121) | 88.26th | v4 (v2025.03.14) |
| Jul 4, 2025 | 9.06% (0.09057) | 92.26th | v4 (v2025.03.14) |
| Jul 1, 2025 | 4.12% (0.04121) | 88.18th | v4 (v2025.03.14) |
| Jun 4, 2025 | 9.06% (0.09057) | 92.19th | v4 (v2025.03.14) |
| Jun 1, 2025 | 4.12% (0.04121) | 88.11th | v4 (v2025.03.14) |
| May 4, 2025 | 9.06% (0.09057) | 92.16th | v4 (v2025.03.14) |
| May 1, 2025 | 4.12% (0.04121) | 88.02th | v4 (v2025.03.14) |
| Mar 30, 2025 | 9.06% (0.09057) | 91.85th | v4 (v2025.03.14) |
| Mar 29, 2025 | 39.44% (0.39440) | 95.92th | v4 (v2025.03.14) |
| Mar 24, 2025 | 9.06% (0.09057) | 91.86th | v4 (v2025.03.14) |
| Mar 23, 2025 | 13.30% (0.13300) | 93.20th | v4 (v2025.03.14) |
| Mar 17, 2025 | 9.06% (0.09057) | 92.02th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.28% (0.00282) | 69.42th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.33% (0.00334) | 70.40th | v3 (v2023.03.01) |
| Jul 21, 2023 | 0.34% (0.00338) | 67.50th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.48% (0.00477) | 71.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 16.31% (0.16306) | 96.13th | v2 (v2022.01.01) |
| Apr 1, 2022 | 16.31% (0.16306) | 95.78th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.31% (0.16306) | 92.84th | v2 (v2022.01.01) |
| Feb 3, 2022 | 13.34% (0.13340) | 89.09th | v1 |
| Jan 6, 2022 | 13.34% (0.13340) | 88.96th | v1 |
| Sep 1, 2021 | 13.34% (0.13340) | 96.02th | v1 |
| Apr 14, 2021 | 13.34% (0.13340) | 0.00th | v1 |
References (23)
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/03/22/1 mailing-listx_refsource_MLISTExploitMailing ListMitigationPatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0796 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1147 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1149 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1289 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-5419 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1689160 Issue Tracking
- https://github.com/advisories/GHSA-m63j-wh5w-c252 Advisory
- https://github.com/rails/rails/commit/f4c70c2222180b8d9d924f00af0c7fd632e26715
- https://github.com/rails/rails/pull/35708
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2019-5419.yml
- https://groups.google.com/forum/#!msg/rubyonrails-security/GN7w9fFAQeI/0iQIiLP2CgAJ
- https://groups.google.com/forum/#!topic/rubyonrails-security/GN7w9fFAQeI
- https://groups.google.com/forum/#%21topic/rubyonrails-security/GN7w9fFAQeI x_refsource_CONFIRM
- https://lists.debian.org/debian-lts-announce/2019/03/msg00042.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/
- https://nvd.nist.gov/vuln/detail/CVE-2019-5419
- https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ x_refsource_CONFIRMPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-5419
Change history (0)
No recorded changes yet.