Описание
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 49.1-1 |
| esm-infra-legacy/xenial | released | 3.18.1-1ubuntu4+esm1 |
| esm-infra/bionic | released | 3.26.0-1ubuntu2+esm1 |
| esm-infra/focal | released | 3.36.2-0ubuntu1.1+esm1 |
| jammy | released | 42.1-1ubuntu0.2 |
| noble | released | 42.2-1ubuntu0.24.04.2 |
| questing | ignored | end of life, was needed |
| resolute | released | 49.0-5ubuntu0.1 |
| upstream | released | 49.1-1 |
Показывать по
Ссылки на источники
7.1 High
CVSS3
Связанные уязвимости
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security ...
7.1 High
CVSS3