A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade yelp-libsUpgrade yelp-xslUpgrade yelpUpgrade yelp-devel | May 20, 2025 | Apr 3, 2025 |
| Alpine Linux | — | Upgrade yelp-xslUpgrade yelp | Aug 8, 2025 | Apr 3, 2025 |
| Amazon Linux Ami 2 | — | Upgrade yelp-debuginfoUpgrade yelpUpgrade yelp-libsUpgrade yelp-develUpgrade yelp-xsl-develUpgrade yelp-xsl | May 30, 2025 | Apr 3, 2025 |
| Debian | — | Upgrade yelpUpgrade yelp-xsl | May 15, 2025 | Apr 3, 2025 |
| Freebsd | — | Upgrade yelp-xslUpgrade yelp | Jun 21, 2025 | Jun 14, 2025 |
| Oracle_linux | — | Upgrade yelpUpgrade yelp-develUpgrade yelp-xslUpgrade yelp-libs | May 19, 2025 | Apr 3, 2025 |
| Redhat_linux | — | Upgrade yelp-develUpgrade yelp-debugsourceUpgrade yelp-libsUpgrade yelp-debuginfoUpgrade yelp-libs-debuginfoUpgrade yelp-xslNo solution existsUpgrade yelp | May 6, 2025 | Apr 3, 2025 |
| Rocky_linux | — | Upgrade yelpUpgrade yelp-debugsourceUpgrade yelp-libs-debuginfoUpgrade yelp-libsUpgrade yelp-debuginfoUpgrade yelp-devel | Jul 31, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade yelp-develUpgrade yelp-langUpgrade yelp-xslUpgrade yelpUpgrade libyelp0 | Jun 30, 2025 | Apr 3, 2025 |
| Ubuntu | — | Upgrade yelp-xslUpgrade yelp | Apr 24, 2025 | Apr 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub