Improper error handling in the routing mechanism could result in directory listings being returned to clients when “Accept: text/html” headers were missing. This could expose file structure or sensitive information about the application environment. Versions affected: 5.0 to 5.0.2 and 4.5 to 4.5.6 Versions fixed: 5.0.3 and 4.5.7