{"schema_version":"1.7.3","id":"GHSA-86g5-2wh3-gc9j","published":"2019-03-13T17:26:59Z","modified":"2025-10-22T19:37:47.266681Z","aliases":["CVE-2019-5418"],"summary":"Path Traversal in Action View","details":"# File Content Disclosure in Action View\n\nImpact \n------ \nThere is a possible file content disclosure vulnerability in Action View.  Specially crafted accept headers in combination with calls to `render file:`  can cause arbitrary files on the target server to be rendered, disclosing the  file contents. \n\nThe impact is limited to calls to `render` which render file contents without  a specified accept format.  Impacted code in a controller looks something like this: \n\n``` ruby\nclass UserController < ApplicationController \n  def index \n    render file: \"#{Rails.root}/some/file\" \n  end \nend \n``` \n\nRendering templates as opposed to files is not impacted by this vulnerability. \n\nAll users running an affected release should either upgrade or use one of the workarounds immediately. \n\nReleases \n-------- \nThe 6.0.0.beta3, 5.2.2.1, 5.1.6.2, 5.0.7.2, and 4.2.11.1 releases are available at the normal locations. \n\nWorkarounds \n----------- \nThis vulnerability can be mitigated by specifying a format for file rendering, like this: \n\n``` ruby\nclass UserController < ApplicationController \n  def index \n    render file: \"#{Rails.root}/some/file\", formats: [:html] \n  end \nend \n``` \n\nIn summary, impacted calls to `render` look like this: \n\n``` \nrender file: \"#{Rails.root}/some/file\" \n``` \n\nThe vulnerability can be mitigated by changing to this: \n\n``` \nrender file: \"#{Rails.root}/some/file\", formats: [:html] \n``` \n\nOther calls to `render` are not impacted. \n\nAlternatively, the following monkey patch can be applied in an initializer: \n\n``` ruby\n$ cat config/initializers/formats_filter.rb \n# frozen_string_literal: true \n\nActionDispatch::Request.prepend(Module.new do \n  def formats \n    super().select do |format| \n      format.symbol || format.ref == \"*/*\" \n    end \n  end \nend) \n``` \n\nCredits \n------- \nThanks to John Hawthorn <john@hawthorn.email> of GitHub","affected":[{"package":{"name":"actionview","ecosystem":"RubyGems","purl":"pkg:gem/actionview"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.0"},{"fixed":"5.2.2.1"}]}],"versions":["5.2.0","5.2.1","5.2.1.1","5.2.1.rc1","5.2.2","5.2.2.rc1"],"database_specific":{"last_known_affected_version_range":"<= 5.2.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-86g5-2wh3-gc9j/GHSA-86g5-2wh3-gc9j.json"}},{"package":{"name":"actionview","ecosystem":"RubyGems","purl":"pkg:gem/actionview"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.2.11.1"}]}],"versions":["4.1.0","4.1.0.beta1","4.1.0.beta2","4.1.0.rc1","4.1.0.rc2","4.1.1","4.1.10","4.1.10.rc1","4.1.10.rc2","4.1.10.rc3","4.1.10.rc4","4.1.11","4.1.12","4.1.12.rc1","4.1.13","4.1.13.rc1","4.1.14","4.1.14.1","4.1.14.2","4.1.14.rc1","4.1.14.rc2","4.1.15","4.1.15.rc1","4.1.16","4.1.16.rc1","4.1.2","4.1.2.rc1","4.1.2.rc2","4.1.2.rc3","4.1.3","4.1.4","4.1.5","4.1.6","4.1.6.rc1","4.1.6.rc2","4.1.7","4.1.7.1","4.1.8","4.1.9","4.1.9.rc1","4.2.0","4.2.0.beta1","4.2.0.beta2","4.2.0.beta3","4.2.0.beta4","4.2.0.rc1","4.2.0.rc2","4.2.0.rc3","4.2.1","4.2.1.rc1","4.2.1.rc2","4.2.1.rc3","4.2.1.rc4","4.2.10","4.2.10.rc1","4.2.11","4.2.2","4.2.3","4.2.3.rc1","4.2.4","4.2.4.rc1","4.2.5","4.2.5.1","4.2.5.2","4.2.5.rc1","4.2.5.rc2","4.2.6","4.2.6.rc1","4.2.7","4.2.7.1","4.2.7.rc1","4.2.8","4.2.8.rc1","4.2.9","4.2.9.rc1","4.2.9.rc2"],"database_specific":{"last_known_affected_version_range":"<= 4.2.11.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-86g5-2wh3-gc9j/GHSA-86g5-2wh3-gc9j.json"}},{"package":{"name":"actionview","ecosystem":"RubyGems","purl":"pkg:gem/actionview"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1.0"},{"fixed":"5.1.6.2"}]}],"versions":["5.1.0","5.1.1","5.1.2","5.1.2.rc1","5.1.3","5.1.3.rc1","5.1.3.rc2","5.1.3.rc3","5.1.4","5.1.4.rc1","5.1.5","5.1.5.rc1","5.1.6","5.1.6.1"],"database_specific":{"last_known_affected_version_range":"<= 5.1.6.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-86g5-2wh3-gc9j/GHSA-86g5-2wh3-gc9j.json"}},{"package":{"name":"actionview","ecosystem":"RubyGems","purl":"pkg:gem/actionview"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.7.2"}]}],"versions":["5.0.0","5.0.0.1","5.0.1","5.0.1.rc1","5.0.1.rc2","5.0.2","5.0.2.rc1","5.0.3","5.0.4","5.0.4.rc1","5.0.5","5.0.5.rc1","5.0.5.rc2","5.0.6","5.0.6.rc1","5.0.7","5.0.7.1"],"database_specific":{"last_known_affected_version_range":"<= 5.0.7.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-86g5-2wh3-gc9j/GHSA-86g5-2wh3-gc9j.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5418"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:0796"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1147"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1149"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1289"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/rubyonrails-security/pFRKI96Sm8Q"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/rubyonrails-security/zRNVOUhKHrg"},{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/rubyonrails-security/pFRKI96Sm8Q"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/03/msg00042.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA"},{"type":"WEB","url":"https://web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released"},{"type":"WEB","url":"https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-5418"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/46585"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/152178/Rails-5.2.1-Arbitrary-File-Content-Disclosure.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/03/22/1"}],"database_specific":{"cwe_ids":["CWE-22"],"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:24:34Z","nvd_published_at":"2019-03-27T14:29:01Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H"}]}