Описание
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Отчет
This vulnerability affects the Content Security Policy (CSP) implementation handling help documents rendered outside the application container via the Flatpak OpenURI portal. Red Hat Product Security has rated this issue as Important. The flaw is caused by an overly permissive Content Security Policy (CSP) implementation that allows attacker-controlled help content to bypass Flatpak's intended sandbox isolation. A malicious Flatpak application can invoke Yelp through the standard OpenURI portal and supply crafted help content that causes the application to access and disclose arbitrary user-readable files from the host system. Unlike typical local file disclosure vulnerabilities, exploitation does not require privileges on the vulnerable Yelp application itself. A malicious Flatpak application can invoke Yelp through the standard OpenURI portal without requiring additional authorization or user interaction beyond running the application. Because the vulnerability enables a sandboxed Flatpak application to access resources outside its intended security boundary by leveraging the host's Yelp application, Red Hat Product Security considers this a cross-boundary information disclosure vulnerability. Under these conditions, an attacker may disclose arbitrary user-readable files from the host system. The currently available analysis does not demonstrate impacts to integrity or availability.
Меры по смягчению последствий
No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update when they becomes available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | yelp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | yelp | Affected | ||
| Red Hat Enterprise Linux 8 | yelp | Affected | ||
| Red Hat Enterprise Linux 9 | yelp | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.1 High
CVSS3
Связанные уязвимости
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security ...
7.1 High
CVSS3