Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-5418

99
FAUCET Score

CVE-2019-5418 is a critical file content disclosure vulnerability affecting multiple versions of Ruby on Rails, including Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1, and v3, as well as various Linux distributions. An unauthenticated attacker can exploit this flaw remotely by sending specially crafted accept headers, leading to the exposure of arbitrary files on the target system. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and severe impact on confidentiality. This CVE is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered substantial community discussion and media coverage, underscoring its importance for immediate remediation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 4.2.11.1CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.0.7.2CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
>= 5.1.0, < 5.1.6.2CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
>= 5.2.0, < 5.2.2.1CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
98.51%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Jul 7, 2025
Nuclei: CVE-2019-5418 · Apr 8, 2020
ExploitDB: EDB-46585 · Mar 21, 2019
This CVE's current EPSS score of 0.9851 is in the 100th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (29)

arubapatch availablevia llm_extracted
Fixed in: 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, 6.0.0.beta3
View patch
boschpatch availablevia llm_extracted
Fixed in: 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, 6.0.0.beta3
View patch
infobloxpatch availablevia llm_extracted
Fixed in: 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, 6.0.0.beta3
View patch
nessuspatch availablevia llm_extracted
Fixed in: 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, 6.0.0.beta3
View patch
power_bipatch availablevia llm_extracted
Fixed in: 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, 6.0.0.beta3
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-gemset-0:5.10.3.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-0:5.9.9.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-amazon-smartstate-0:5.9.9.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-appliance-0:5.9.9.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-gemset-0:5.9.9.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-ror50-rubygem-actionpack-1:5.0.1-2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-ror50-rubygem-actionpack-1:5.0.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-ror42-rubygem-actionpack-1:4.2.6-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-ror42-rubygem-actionpack-1:4.2.6-5.el6
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: ansible-tower-0:3.4.3-1.el7at
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-0:5.10.3.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-amazon-smartstate-0:5.10.3.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-appliance-0:5.10.3.3-1.el7cf
View patch
rubygemspatch availablevia ghsa
Product: actionviewFixed in: 5.1.6.2
rubygemspatch availablevia ghsa
Product: actionviewFixed in: 4.2.11.1
rubygemspatch availablevia ghsa
Product: actionviewFixed in: 5.2.2.1
rubygemspatch availablevia ghsa
Product: actionviewFixed in: 5.0.7.2
vmwarepatch availablevia llm_extracted
Fixed in: 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, 6.0.0.beta3
View patch

Vendor Advisories (8)

rubygemsGHSA-86g5-2wh3-gc9jhigh

Path Traversal in Action View

Mar 13, 2019
redhatCVE-2019-5418Important

rubygem-actionpack: render file directory traversal in Action View

Mar 13, 2019
aruballm-aruba-4ebe13fa3638e127HIGH

Rails 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, and 6.0.0.beta3 have been released!

Mar 13, 2019
vmwarellm-vmware-a7f49dc294fdf5d4HIGH

Rails 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, and 6.0.0.beta3 have been released!

Mar 13, 2019
infobloxllm-infoblox-dc8d4b76db1b7dfbHIGH

Rails 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, and 6.0.0.beta3 have been released!

Mar 13, 2019
power_billm-power_bi-225a973cb758f893HIGH

Rails 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, and 6.0.0.beta3 have been released!

Mar 13, 2019
boschllm-bosch-03b19d8072da1514HIGH

Rails 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, and 6.0.0.beta3 have been released!

Mar 13, 2019
nessusllm-nessus-ceb804e768466085HIGH

Rails 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, and 6.0.0.beta3 have been released!

Mar 13, 2019

References

web.archive.org / web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released
PatchVendor Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
lists.opensuse.org / opensuse-security-announce/2019-05/msg00011.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/152178/Rails-5.2.1-Arbitrary-File-Content-Disclosure.html
ExploitThird Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:0796
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1147
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1149
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1289
Third Party Advisory
groups.google.com / forum
Permissions Required
lists.debian.org / debian-lts-announce/2019/03/msg00042.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA
Third Party Advisory
weblog.rubyonrails.org / 2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released
Broken LinkPatchVendor Advisory
exploit-db.com / exploits/46585
ExploitThird Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2019/03/22/1
Mailing ListMitigationPatchThird Party Advisory