There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target systems filesystem to be exposed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rails | Rubyonrails | 3.0.0 (including) | 4.2.11.1 (excluding) |
Rails | Rubyonrails | 5.0.0 (including) | 5.0.7.2 (excluding) |
Rails | Rubyonrails | 5.1.0 (including) | 5.1.6.2 (excluding) |
Rails | Rubyonrails | 5.2.0 (including) | 5.2.2.1 (excluding) |