Описание
ELSA-2026-47177: yelp security update (IMPORTANT)
[2:3.28.1-3.2]
- Fix CVE-2026-13601 (RHEL-190226)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
yelp
3.28.1-3.el8_10.2
yelp-devel
3.28.1-3.el8_10.2
yelp-libs
3.28.1-3.el8_10.2
Oracle Linux x86_64
yelp
3.28.1-3.el8_10.2
yelp-devel
3.28.1-3.el8_10.2
yelp-libs
3.28.1-3.el8_10.2
Связанные CVE
Связанные уязвимости
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security ...