漏洞描述
Rails <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 are susceptible to a file content disclosure vulnerability because specially crafted accept headers can cause contents of arbitrary files on the target system's file system to be exposed.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/omarkurt/CVE-2019-5418↗weblog.rubyonrails.orghttps://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-5418↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.html↗