Bug 1689160 (CVE-2019-5419) - CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View
Summary: CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-5419
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1689161 1690395 1690396 1690398 1690400 1696009 1696010
Blocks: 1689162
TreeView+ depends on / blocked
 
Reported: 2019-03-15 10:29 UTC by Andrej Nemec
Modified: 2019-09-29 15:09 UTC (History)
19 users (show)

Fixed In Version: rubygem-actionview 6.0.0.beta3, rubygem-actionview 5.2.2.1, rubygem-actionview 5.1.6.2, rubygem-actionview 5.0.7.2, rubygem-actionview 4.2.11.1
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-05-13 09:43:02 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:0796 None None None 2019-04-23 07:46:22 UTC
Red Hat Product Errata RHSA-2019:1147 None None None 2019-05-13 08:52:13 UTC
Red Hat Product Errata RHSA-2019:1149 None None None 2019-05-13 09:11:32 UTC
Red Hat Product Errata RHSA-2019:1289 None None None 2019-05-29 12:41:11 UTC

Description Andrej Nemec 2019-03-15 10:29:53 UTC
Specially crafted accept headers can cause the Action View template location
code to consume 100% CPU, causing the server unable to process requests.  This
impacts all Rails applications that render views.


External References:

https://groups.google.com/forum/#!msg/rubyonrails-security/GN7w9fFAQeI/0iQIiLP2CgAJ

Comment 1 Andrej Nemec 2019-03-15 10:30:35 UTC
Created rubygem-actionview tracking bugs for this issue:

Affects: fedora-all [bug 1689161]

Comment 2 Andrej Nemec 2019-03-15 10:32:43 UTC
References:

https://seclists.org/oss-sec/2019/q1/177

Comment 5 Stefan Cornelius 2019-03-20 10:10:44 UTC
Statement:

This issue did affect the versions of rh-ror42-rubygem-actionview and rh-ror50-rubygem-actionview as shipped with Red Hat Software Collections.

Comment 8 errata-xmlrpc 2019-04-23 07:46:21 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.10

Via RHSA-2019:0796 https://access.redhat.com/errata/RHSA-2019:0796

Comment 10 errata-xmlrpc 2019-05-13 08:52:12 UTC
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 6
  Red Hat Software Collections for Red Hat Enterprise Linux 7
  Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS

Via RHSA-2019:1147 https://access.redhat.com/errata/RHSA-2019:1147

Comment 11 errata-xmlrpc 2019-05-13 09:11:31 UTC
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 6
  Red Hat Software Collections for Red Hat Enterprise Linux 7
  Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS

Via RHSA-2019:1149 https://access.redhat.com/errata/RHSA-2019:1149

Comment 12 errata-xmlrpc 2019-05-29 12:41:10 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.9

Via RHSA-2019:1289 https://access.redhat.com/errata/RHSA-2019:1289


Note You need to log in before you can comment on or make changes to this bug.