Lucene search

K
redhatcveRedhat.comRH:CVE-2019-5418
HistoryNov 06, 2019 - 10:28 a.m.

CVE-2019-5418

2019-11-0610:28:57
redhat.com
access.redhat.com
18

0.975 High

EPSS

Percentile

100.0%

A content disclosure flaw was found in rubygem-actionview. Specially crafted accept headers, in combination with calls to ‘render file:’, can cause arbitrary files on the target server to be rendered, disclosing the file contents. Code execution cannot be ruled out if the attacker is able to gain access to the proper files. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.