CVE-2019-5418

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 04, 2019
Published Date
March 27, 2019
Last Updated
July 30, 2025
Vendor
Rails
Product
https://github.com/rails/rails
Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
Tags
ruby cisa nuclei_scanner

CVSS Scores

CVSS v3.1

7.5 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2.0

5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Score

Score
94.34% (Percentile: 99.94%) as of 2025-07-29

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2025-07-07 17:45:30 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-07-07 17:45:23 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

daehyeok0618/CVE-2019-5418

Type: github • Created: 2025-04-07 16:55:22 UTC • Stars: 0

WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.

kailing0220/CVE-2019-5418

Type: github • Created: 2022-10-17 09:04:43 UTC • Stars: 2

Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图,我们可以通过修改访问某控制器的请求包,通过“…/…/…/…/”来达到路径穿越的目的,然后再通过“{{”来进行模板查询路径的闭合,使得所要访问的文件被当做外部模板来解析。

random-robbie/CVE-2019-5418

Type: github • Created: 2019-11-19 09:40:06 UTC • Stars: 5

takeokunn/CVE-2019-5418

Type: github • Created: 2019-03-30 07:40:11 UTC • Stars: 2

brompwnie/CVE-2019-5418-Scanner

Type: github • Created: 2019-03-19 15:38:01 UTC • Stars: 35

A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418

omarkurt/CVE-2019-5418

Type: github • Created: 2019-03-18 16:09:13 UTC • Stars: 5

File Content Disclosure on Rails Test Case - CVE-2019-5418

mpgn/CVE-2019-5418

Type: github • Created: 2019-03-16 11:58:18 UTC • Stars: 195

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel