A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade yelp-develUpgrade yelpUpgrade yelp-xslUpgrade yelp-libs | May 20, 2025 | Apr 3, 2025 |
| Alpine Linux | — | Upgrade yelpUpgrade yelp-xsl | Aug 8, 2025 | Apr 3, 2025 |
| Amazon Linux Ami 2 | — | Upgrade yelp-develUpgrade yelp-xsl-develUpgrade yelp-xslUpgrade yelpUpgrade yelp-libsUpgrade yelp-debuginfo | May 30, 2025 | Apr 3, 2025 |
| Debian | — | Upgrade yelp-xslUpgrade yelp | May 15, 2025 | Apr 3, 2025 |
| Freebsd | — | Upgrade yelp-xslUpgrade yelp | Jun 21, 2025 | Jun 14, 2025 |
| Oracle_linux | — | Upgrade yelp-libsUpgrade yelpUpgrade yelp-xslUpgrade yelp-devel | May 19, 2025 | Apr 3, 2025 |
| Redhat_linux | — | Upgrade yelp-develUpgrade yelp-debugsourceUpgrade yelp-libsUpgrade yelp-debuginfoUpgrade yelp-libs-debuginfoNo solution existsUpgrade yelp-xslUpgrade yelp | May 6, 2025 | Apr 3, 2025 |
| Rocky_linux | — | Upgrade yelpUpgrade yelp-debugsourceUpgrade yelp-develUpgrade yelp-libs-debuginfoUpgrade yelp-libsUpgrade yelp-debuginfo | Jul 31, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade yelp-develUpgrade yelpUpgrade yelp-xslUpgrade yelp-langUpgrade libyelp0 | Jun 30, 2025 | Apr 3, 2025 |
| Ubuntu | — | Upgrade yelp-xslUpgrade yelp | Apr 24, 2025 | Apr 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub