Описание
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Отчет
Red Hat has evaluated this with a Important severity as this requires user interaction and possibly access to add malicious JavaScript content, allowing the attacker to exfiltrate files from the victim's end with minimal user interaction.
Меры по смягчению последствий
Currently, no mitigation is available for this vulnerability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | yelp | Out of support scope | ||
Red Hat Enterprise Linux 7 | yelp | Out of support scope | ||
Red Hat Enterprise Linux 8 | yelp | Fixed | RHSA-2025:7569 | 14.05.2025 |
Red Hat Enterprise Linux 8 | yelp-xsl | Fixed | RHSA-2025:7569 | 14.05.2025 |
Red Hat Enterprise Linux 8.2 Advanced Update Support | yelp | Fixed | RHSA-2025:4457 | 05.05.2025 |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | yelp | Fixed | RHSA-2025:4451 | 05.05.2025 |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | yelp | Fixed | RHSA-2025:4451 | 05.05.2025 |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | yelp | Fixed | RHSA-2025:4451 | 05.05.2025 |
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | yelp | Fixed | RHSA-2025:4455 | 05.05.2025 |
Red Hat Enterprise Linux 8.6 Telecommunications Update Service | yelp | Fixed | RHSA-2025:4455 | 05.05.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
A flaw was found in Yelp. The Gnome user help application allows the h ...
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
ELSA-2025-7569: yelp and yelp-xsl security update (IMPORTANT)
EPSS
7.4 High
CVSS3