CVE-2019-5418
HIGH KEV NUCLEIRuby On Rails File Content Disclosure (
Title source: metasploitDescription
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
Exploits (12)
exploitdb
WORKING POC
by NotoriousRebel · pythonwebappsmultiple
https://www.exploit-db.com/exploits/46585
Nuclei Templates (1)
Rails File Content Disclosure
HIGHby omarkurt
Shodan:
cpe:"cpe:2.3:a:rubyonrails:rails"
References (14)
Scores
CVSS v3
7.5
EPSS
0.9434
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation Intel
CISA KEV
2025-07-07
VulnCheck KEV
2025-07-07
ENISA EUVD
EUVD-2019-0375
Classification
CWE
CWE-22
Status
published
Affected Products (8)
rubyonrails/rails
< 4.2.11.1
debian/debian_linux
redhat/cloudforms
opensuse/leap
fedoraproject/fedora
redhat/cloudforms
redhat/software_collections
rubygems/actionview
< 5.2.2.1RubyGems
Timeline
Published
Mar 27, 2019
KEV Added
Jul 07, 2025
Tracked Since
Feb 18, 2026