Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3155

Опубликовано: 03 апр. 2025
Источник: redhat
CVSS3: 7.4
EPSS Средний

Описание

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

Отчет

Red Hat has evaluated this with a Important severity as this requires user interaction and possibly access to add malicious JavaScript content, allowing the attacker to exfiltrate files from the victim's end with minimal user interaction.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6yelpOut of support scope
Red Hat Enterprise Linux 7yelpAffected
Red Hat Enterprise Linux 7yelp-xslAffected
Red Hat Enterprise Linux 9yelp-xslAffected
Red Hat Enterprise Linux 8yelpFixedRHSA-2025:756914.05.2025
Red Hat Enterprise Linux 8yelp-xslFixedRHSA-2025:756914.05.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportyelpFixedRHSA-2025:445705.05.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportyelpFixedRHSA-2025:445105.05.2025
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceyelpFixedRHSA-2025:445105.05.2025
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsyelpFixedRHSA-2025:445105.05.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-601

EPSS

Процентиль: 96%
0.12393
Средний

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 1 года назад

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

CVSS3: 7.4
nvd
больше 1 года назад

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

CVSS3: 7.4
debian
больше 1 года назад

A flaw was found in Yelp. The Gnome user help application allows the h ...

suse-cvrf
8 месяцев назад

Security update for yelp

suse-cvrf
около 1 года назад

Security update for yelp

EPSS

Процентиль: 96%
0.12393
Средний

7.4 High

CVSS3