Bug 1689160 (CVE-2019-5419)

Summary: CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dajohnso, dmetzger, gblomqui, gmccullo, gtanzill, hhorak, jaruga, jfrey, jhardy, jorton, jprause, kdixon, obarenbo, pvalena, roliveri, ruby-maint, ruby-packagers-sig, simaishi, strzibny
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rubygem-actionview 6.0.0.beta3, rubygem-actionview 5.2.2.1, rubygem-actionview 5.1.6.2, rubygem-actionview 5.0.7.2, rubygem-actionview 4.2.11.1 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-05-13 09:43:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1689161, 1690395, 1690396, 1690398, 1690400, 1696009, 1696010    
Bug Blocks: 1689162    

Description Andrej Nemec 2019-03-15 10:29:53 UTC
Specially crafted accept headers can cause the Action View template location
code to consume 100% CPU, causing the server unable to process requests.  This
impacts all Rails applications that render views.


External References:

https://groups.google.com/forum/#!msg/rubyonrails-security/GN7w9fFAQeI/0iQIiLP2CgAJ

Comment 1 Andrej Nemec 2019-03-15 10:30:35 UTC
Created rubygem-actionview tracking bugs for this issue:

Affects: fedora-all [bug 1689161]

Comment 2 Andrej Nemec 2019-03-15 10:32:43 UTC
References:

https://seclists.org/oss-sec/2019/q1/177

Comment 5 Stefan Cornelius 2019-03-20 10:10:44 UTC
Statement:

This issue did affect the versions of rh-ror42-rubygem-actionview and rh-ror50-rubygem-actionview as shipped with Red Hat Software Collections.

Comment 8 errata-xmlrpc 2019-04-23 07:46:21 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.10

Via RHSA-2019:0796 https://access.redhat.com/errata/RHSA-2019:0796

Comment 10 errata-xmlrpc 2019-05-13 08:52:12 UTC
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 6
  Red Hat Software Collections for Red Hat Enterprise Linux 7
  Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS

Via RHSA-2019:1147 https://access.redhat.com/errata/RHSA-2019:1147

Comment 11 errata-xmlrpc 2019-05-13 09:11:31 UTC
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 6
  Red Hat Software Collections for Red Hat Enterprise Linux 7
  Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS

Via RHSA-2019:1149 https://access.redhat.com/errata/RHSA-2019:1149

Comment 12 errata-xmlrpc 2019-05-29 12:41:10 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.9

Via RHSA-2019:1289 https://access.redhat.com/errata/RHSA-2019:1289