CVE-2019-5419

Source
https://cve.org/CVERecord?id=CVE-2019-5419
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5419.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-5419
Aliases
Downstream
Related
Published
2019-03-27T14:29:01.657Z
Modified
2026-02-17T07:30:27.403390Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.

References

Affected packages

Git / github.com/rails/rails

Affected ranges

Affected versions

v5.*
v5.0.0
v5.0.0.1
v5.0.1
v5.0.1.rc1
v5.0.1.rc2
v5.0.2
v5.0.2.rc1
v5.0.3
v5.0.4
v5.0.4.rc1
v5.0.5
v5.0.5.rc1
v5.0.5.rc2
v5.0.6
v5.0.7
v5.0.7.1
v5.1.0
v5.1.1
v5.1.2
v5.1.2.rc1
v5.1.3
v5.1.3.rc1
v5.1.3.rc2
v5.1.3.rc3
v5.1.4
v5.1.4.rc1
v5.1.5
v5.1.5.rc1
v5.1.6
v5.1.6.1
v5.2.0
v5.2.1
v5.2.1.1
v5.2.1.rc1
v5.2.2
v5.2.2.rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5419.json"