Описание
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as High, as it enables remote websites to extract arbitrary files from a user’s system with minimal interaction. Although some user action is required, the action can be trivial and easily induced by a malicious page. The issue arises from missing validation that a dragged file originated from an external application, enabling unintended file system access. Successful exploitation can compromise confidentiality of local user data.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | ||
| Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix | ||
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | webkitgtk4 | Fixed | RHSA-2025:23583 | 18.12.2025 |
| Red Hat Enterprise Linux 8 | webkit2gtk3 | Fixed | RHSA-2025:22789 | 08.12.2025 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | webkit2gtk3 | Fixed | RHSA-2025:23433 | 17.12.2025 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | webkit2gtk3 | Fixed | RHSA-2025:23434 | 17.12.2025 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | webkit2gtk3 | Fixed | RHSA-2025:23434 | 17.12.2025 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | webkit2gtk3 | Fixed | RHSA-2025:23743 | 22.12.2025 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | webkit2gtk3 | Fixed | RHSA-2025:23743 | 22.12.2025 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | webkit2gtk3 | Fixed | RHSA-2025:23743 | 22.12.2025 |
Показывать по
Дополнительная информация
Статус:
7.4 High
CVSS3
Связанные уязвимости
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
A flaw was found in WebKitGTK. This vulnerability allows remote, user- ...
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
Уязвимость модулей отображения веб-страниц WPE WebKit и WebKitGTK, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
7.4 High
CVSS3