Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-47177

Опубликовано: 28 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-47177: yelp security update (IMPORTANT)

[2:3.28.1-3.2]

  • Fix CVE-2026-13601 (RHEL-190226)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

yelp

3.28.1-3.el8_10.2

yelp-devel

3.28.1-3.el8_10.2

yelp-libs

3.28.1-3.el8_10.2

Oracle Linux x86_64

yelp

3.28.1-3.el8_10.2

yelp-devel

3.28.1-3.el8_10.2

yelp-libs

3.28.1-3.el8_10.2

Связанные CVE

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
redhat
3 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
nvd
около 1 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
debian
около 1 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security ...

suse-cvrf
21 день назад

Security update for yelp