EXPOSURES › CVE-2019-5418
CVE-2019-5418
HIGH ⌖ ON CISA KEV · EXPLOITEDRuby on Rails exposed to file disclosure via path traversal
Ruby on Rails, a component of many web applications, was found to allow attackers to read arbitrary files on the server by manipulating the 'render file:' call with specially crafted accept headers. This vulnerability was actively exploited in the wild, posing a significant security risk to DIB organizations using the affected software.
Shame score — Active exploitation in the wild indicates a severe and ongoing risk to DIB systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.