Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3155

Опубликовано: 03 апр. 2025
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

Отчет

Red Hat has evaluated this with a Important severity as this requires user interaction and possibly access to add malicious JavaScript content, allowing the attacker to exfiltrate files from the victim's end with minimal user interaction.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6yelpOut of support scope
Red Hat Enterprise Linux 7yelpOut of support scope
Red Hat Enterprise Linux 8yelpFixedRHSA-2025:756914.05.2025
Red Hat Enterprise Linux 8yelp-xslFixedRHSA-2025:756914.05.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportyelpFixedRHSA-2025:445705.05.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportyelpFixedRHSA-2025:445105.05.2025
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceyelpFixedRHSA-2025:445105.05.2025
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsyelpFixedRHSA-2025:445105.05.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportyelpFixedRHSA-2025:445505.05.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceyelpFixedRHSA-2025:445505.05.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-829

EPSS

Процентиль: 26%
0.00086
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

CVSS3: 7.4
nvd
3 месяца назад

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

CVSS3: 7.4
debian
3 месяца назад

A flaw was found in Yelp. The Gnome user help application allows the h ...

CVSS3: 6.5
github
3 месяца назад

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

oracle-oval
около 1 месяца назад

ELSA-2025-7569: yelp and yelp-xsl security update (IMPORTANT)

EPSS

Процентиль: 26%
0.00086
Низкий

7.4 High

CVSS3