Specially crafted accept headers can cause the Action View template location code to consume 100% CPU, causing the server unable to process requests. This impacts all Rails applications that render views. External References: https://groups.google.com/forum/#!msg/rubyonrails-security/GN7w9fFAQeI/0iQIiLP2CgAJ
Created rubygem-actionview tracking bugs for this issue: Affects: fedora-all [bug 1689161]
References: https://seclists.org/oss-sec/2019/q1/177
Statement: This issue did affect the versions of rh-ror42-rubygem-actionview and rh-ror50-rubygem-actionview as shipped with Red Hat Software Collections.
Upstream commit: 4.2 https://github.com/rails/rails/commit/58ed245e80a8710fbe31e91417bfd19f9f934cc4 5.0 https://github.com/rails/rails/commit/c79dcbce9bfd20fe7f72ca431c49965ee39bd645 5.1 https://github.com/rails/rails/commit/92c025d7f17ff256ac50f5e3bc014bb1a016d1ec 5.2 https://github.com/rails/rails/commit/d7fac9c09a535ec7f11bb9aa8addb4af37b7d4b5
This issue has been addressed in the following products: CloudForms Management Engine 5.10 Via RHSA-2019:0796 https://access.redhat.com/errata/RHSA-2019:0796
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Via RHSA-2019:1147 https://access.redhat.com/errata/RHSA-2019:1147
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Via RHSA-2019:1149 https://access.redhat.com/errata/RHSA-2019:1149
This issue has been addressed in the following products: CloudForms Management Engine 5.9 Via RHSA-2019:1289 https://access.redhat.com/errata/RHSA-2019:1289