Description
In Action View 5.2.2.1, 5.1.6.2, 5.0.7.2, 4.2.11.1, and v3, specially crafted accept headers can disclose the contents of arbitrary files on the target system’s file system, resulting in a File Content Disclosure vulnerability.
Recommendations
- Update rails to the latest version
Automated human-like penetration testing for your web apps & APIs
Teams using Beagle Security are set up in minutes, embrace release-based CI/CD security testing and save up to 65% with timely remediation of vulnerabilities. Sign up for a free account to see what it can do for you.