Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Ubuntu 18.04 & 16.04: Rails Important Information Exposure CVE-2019-5418

ubuntu
Calendar Grey July 17, 2025
Dist Ubuntu Esm H88
Uncover the vulnerabilities associated with sensitive data breaches in Rails on Ubuntu 18.04 and 16.04 LTS connected to CVE-2019-5418.
Rails could be made to expose sensitive information over the network.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Rails could be made to expose sensitive information over the network. Software Description: - rails: MVC ruby based framework geared for web application development Details: It was discovered that Rails did not correctly handle headers. An attacker could potentially use this issue to view arbitrary files on a target server. (CVE-2019-5418)

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS   rails                           2:4.2.10-0ubuntu4+esm2                                   Available with Ubuntu Pro   ruby-actionpack                 2:4.2.10-0ubuntu4+esm2                                   Available with Ubuntu Pro   ruby-actionview                 2:4.2.10-0ubuntu4+esm2                                   Available with Ubuntu Pro Ubuntu 16.04 LTS   rails                           2:4.2.6-1ubuntu0.1~esm2                                   Available with Ubuntu Pro   ruby-actionpack                 2:4.2.6-1ubuntu0.1~esm2                                   Available with Ubuntu Pro   ruby-actionview                 2:4.2.6-1ubuntu0.1~esm2                                   Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7646-1

  CVE-2019-5418

Severity
important
Lowest
Low
Medium
High
Critical

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here