CVE-2019-5419
published 2019-03-27CVE-2019-5419: There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
8.67%
94.5th percentile
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rails | < rails 2:5.2.2.1+dfsg-1 (bookworm) | rails 2:5.2.2.1+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| rails | actionview | >= 4.0.0 < 4.2.11.1 | 4.2.11.1 |
| rails | actionview | >= 5.0.0 < 5.0.7.2 | 5.0.7.2 |
| rails | actionview | >= 5.1.0 < 5.1.6.2 | 5.1.6.2 |
| rails | actionview | >= 5.2.0 < 5.2.2.1 | 5.2.2.1 |
| rails | actionview | >= 6.0.0.beta1 < 6.0.0.beta3 | 6.0.0.beta3 |
| rails | https_github.com_rails_rails | — | — |
| rails | https_github.com_rails_rails | — | — |
| rails | https_github.com_rails_rails | — | — |
| rails | https_github.com_rails_rails | — | — |
| redhat | cloudforms | — | — |
| redhat | cloudforms | — | — |
| redhat | software_collections | — | — |
| rubyonrails | rails | < 4.2.11.1 | 4.2.11.1 |
| rubyonrails | rails | >= 0 < 2:5.2.2.1+dfsg-1 | 2:5.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.2.1+dfsg-1 | 2:5.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.2.1+dfsg-1 | 2:5.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.2.1+dfsg-1 | 2:5.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 5.0.0 < 5.0.7.2 | 5.0.7.2 |
| rubyonrails | rails | >= 5.1.0 < 5.1.6.2 | 5.1.6.2 |
| rubyonrails | rails | >= 5.2.0 < 5.2.2.1 | 5.2.2.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: denial of service vulnerability in Action View
vendor_redhat·2019-03-13·CVSS 7.5
CVE-2019-5419 [HIGH] CWE-20 rubygem-actionpack: denial of service vulnerability in Action View
rubygem-actionpack: denial of service vulnerability in Action View
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
Statement: This issue did affect the versions of rh-ror42-rubygem-actionview and rh-ror50-rubygem-actionview as shipped with Red Hat Software Collections.
Debian
CVE-2019-5419: rails - There is a possible denial of service vulnerability in Action View (Rails) <5.2....
vendor_debian·2019·CVSS 7.5
CVE-2019-5419 [HIGH] CVE-2019-5419: rails - There is a possible denial of service vulnerability in Action View (Rails) <5.2....
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
Scope: local
bookworm: resolved (fixed in 2:5.2.2.1+dfsg-1)
bullseye: resolved (fixed in 2:5.2.2.1+dfsg-1)
forky: resolved (fixed in 2:5.2.2.1+dfsg-1)
sid: resolved (fixed in 2:5.2.2.1+dfsg-1)
trixie: resolved (fixed in 2:5.2.2.1+dfsg-1)
OSV
CVE-2019-5419: There is a possible denial of service vulnerability in Action View (Rails) <5
osv·2019-03-27·CVSS 7.5
CVE-2019-5419 [HIGH] CVE-2019-5419: There is a possible denial of service vulnerability in Action View (Rails) <5
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
OSV
Denial of Service Vulnerability in Action View
osv·2019-03-13
CVE-2019-5419 [HIGH] Denial of Service Vulnerability in Action View
Denial of Service Vulnerability in Action View
# Denial of Service Vulnerability in Action View
Impact
Specially crafted accept headers can cause the Action View template location code to consume 100% CPU, causing the server unable to process requests. This impacts all Rails applications that render views.
All users running an affected release should either upgrade or use one of the workarounds immediately.
Releases
The 6.0.0.beta3, 5.2.2.1, 5.1.6.2, 5.0.7.2, and 4.2.11.1 releases are available at the normal locations.
Workarounds
This vulnerability can be mitigated by wrapping `render` calls with `respond_to` blocks. For example, the following example is vulnerable:
``` ruby
class UserController of GitHub
GHSA
Denial of Service Vulnerability in Action View
ghsa·2019-03-13
CVE-2019-5419 [HIGH] CWE-400 Denial of Service Vulnerability in Action View
Denial of Service Vulnerability in Action View
# Denial of Service Vulnerability in Action View
Impact
Specially crafted accept headers can cause the Action View template location code to consume 100% CPU, causing the server unable to process requests. This impacts all Rails applications that render views.
All users running an affected release should either upgrade or use one of the workarounds immediately.
Releases
The 6.0.0.beta3, 5.2.2.1, 5.1.6.2, 5.0.7.2, and 4.2.11.1 releases are available at the normal locations.
Workarounds
This vulnerability can be mitigated by wrapping `render` calls with `respond_to` blocks. For example, the following example is vulnerable:
``` ruby
class UserController of GitHub
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5418 rubygem-actionpack: render file directory traversal in Action View
bugzilla·2019-03-15·CVSS 7.5
CVE-2019-5418 [HIGH] CVE-2019-5418 rubygem-actionpack: render file directory traversal in Action View
CVE-2019-5418 rubygem-actionpack: render file directory traversal in Action View
There is a possible file content disclosure vulnerability in Action View.
Specially crafted accept headers in combination with calls to `render file:`
can cause arbitrary files on the target server to be rendered, disclosing the
file contents.
External References:
https://groups.google.com/forum/#!msg/rubyonrails-security/pFRKI96Sm8Q/IhpRq9D2CgAJ
https://github.com/mpgn/CVE-2019-5418
Discussion:
Created rubygem-actionview tracking bugs for this issue:
Affects: fedora-all [bug 1689161]
---
References:
https://seclists.org/oss-sec/2019/q1/178
---
Note the patch to fix this issue is same with CVE-2019-5419.
---
Upstream commit:
4.2 https://github.com/rails/rails/commit/58ed245e80a8710fbe31e91417bfd1
Bugzilla
CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View
bugzilla·2019-03-15·CVSS 7.5
CVE-2019-5419 [HIGH] CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View
CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View
Specially crafted accept headers can cause the Action View template location
code to consume 100% CPU, causing the server unable to process requests. This
impacts all Rails applications that render views.
External References:
https://groups.google.com/forum/#!msg/rubyonrails-security/GN7w9fFAQeI/0iQIiLP2CgAJ
Discussion:
Created rubygem-actionview tracking bugs for this issue:
Affects: fedora-all [bug 1689161]
---
References:
https://seclists.org/oss-sec/2019/q1/177
---
Statement:
This issue did affect the versions of rh-ror42-rubygem-actionview and rh-ror50-rubygem-actionview as shipped with Red Hat Software Collections.
---
Upstream commit:
4.2 https://github.com/rails/rails/commit/58ed245e80a
Bugzilla
CVE-2019-5418 CVE-2019-5419 rubygem-actionview: various flaws [fedora-all]
bugzilla·2019-03-15·CVSS 7.5
CVE-2019-5418 [HIGH] CVE-2019-5418 CVE-2019-5419 rubygem-actionview: various flaws [fedora-all]
CVE-2019-5418 CVE-2019-5419 rubygem-actionview: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.htmlhttp://www.openwall.com/lists/oss-security/2019/03/22/1https://access.redhat.com/errata/RHSA-2019:0796https://access.redhat.com/errata/RHSA-2019:1147https://access.redhat.com/errata/RHSA-2019:1149https://access.redhat.com/errata/RHSA-2019:1289https://groups.google.com/forum/#%21topic/rubyonrails-security/GN7w9fFAQeIhttps://lists.debian.org/debian-lts-announce/2019/03/msg00042.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.htmlhttp://www.openwall.com/lists/oss-security/2019/03/22/1https://access.redhat.com/errata/RHSA-2019:0796https://access.redhat.com/errata/RHSA-2019:1147https://access.redhat.com/errata/RHSA-2019:1149https://access.redhat.com/errata/RHSA-2019:1289https://groups.google.com/forum/#%21topic/rubyonrails-security/GN7w9fFAQeIhttps://lists.debian.org/debian-lts-announce/2019/03/msg00042.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/
2019-03-27
Published