Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-13947

Опубликовано: 03 дек. 2025
Источник: redhat
CVSS3: 7.4

Описание

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as High, as it enables remote websites to extract arbitrary files from a user’s system with minimal interaction. Although some user action is required, the action can be trivial and easily induced by a malicious page. The issue arises from missing validation that a dragged file originated from an external application, enabling unintended file system access. Successful exploitation can compromise confidentiality of local user data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6webkitgtkOut of support scope
Red Hat Enterprise Linux 7webkitgtk3Will not fix
Red Hat Enterprise Linux 7 Extended Lifecycle Supportwebkitgtk4FixedRHSA-2025:2358318.12.2025
Red Hat Enterprise Linux 8webkit2gtk3FixedRHSA-2025:2278908.12.2025
Red Hat Enterprise Linux 8.2 Advanced Update Supportwebkit2gtk3FixedRHSA-2025:2343317.12.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportwebkit2gtk3FixedRHSA-2025:2343417.12.2025
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onwebkit2gtk3FixedRHSA-2025:2343417.12.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportwebkit2gtk3FixedRHSA-2025:2374322.12.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicewebkit2gtk3FixedRHSA-2025:2374322.12.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionswebkit2gtk3FixedRHSA-2025:2374322.12.2025

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2418576webkit: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

CVSS3: 7.4
nvd
4 месяца назад

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

CVSS3: 7.4
debian
4 месяца назад

A flaw was found in WebKitGTK. This vulnerability allows remote, user- ...

CVSS3: 7.4
github
4 месяца назад

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

CVSS3: 7.4
fstec
4 месяца назад

Уязвимость модулей отображения веб-страниц WPE WebKit и WebKitGTK, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

7.4 High

CVSS3