There is a possible file content disclosure vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents. External References: https://groups.google.com/forum/#!msg/rubyonrails-security/pFRKI96Sm8Q/IhpRq9D2CgAJ https://github.com/mpgn/CVE-2019-5418
Created rubygem-actionview tracking bugs for this issue: Affects: fedora-all [bug 1689161]
References: https://seclists.org/oss-sec/2019/q1/178
Note the patch to fix this issue is same with CVE-2019-5419.
Upstream commit: 4.2 https://github.com/rails/rails/commit/58ed245e80a8710fbe31e91417bfd19f9f934cc4 5.0 https://github.com/rails/rails/commit/c79dcbce9bfd20fe7f72ca431c49965ee39bd645 5.1 https://github.com/rails/rails/commit/92c025d7f17ff256ac50f5e3bc014bb1a016d1ec 5.2 https://github.com/rails/rails/commit/d7fac9c09a535ec7f11bb9aa8addb4af37b7d4b5
Statement: This issue did affect the versions of rh-ror42-rubygem-actionpack and rh-ror50-rubygem-actionpack as shipped with Red Hat Software Collections.
This issue has been addressed in the following products: CloudForms Management Engine 5.10 Via RHSA-2019:0796 https://access.redhat.com/errata/RHSA-2019:0796
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Via RHSA-2019:1147 https://access.redhat.com/errata/RHSA-2019:1147
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Via RHSA-2019:1149 https://access.redhat.com/errata/RHSA-2019:1149
This issue has been addressed in the following products: CloudForms Management Engine 5.9 Via RHSA-2019:1289 https://access.redhat.com/errata/RHSA-2019:1289