A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade yelp-develUpgrade yelp-xslUpgrade yelp-libsUpgrade yelp | May 20, 2025 | Apr 3, 2025 |
| Alpine Linux | — | Upgrade yelpUpgrade yelp-xsl | Aug 8, 2025 | Apr 3, 2025 |
| Amazon Linux Ami 2 | — | Upgrade yelp-xsl-develUpgrade yelp-develUpgrade yelp-xslUpgrade yelp-libsUpgrade yelpUpgrade yelp-debuginfo | May 30, 2025 | Apr 3, 2025 |
| Debian | — | Upgrade yelpUpgrade yelp-xsl | May 15, 2025 | Apr 3, 2025 |
| Freebsd | — | Upgrade yelpUpgrade yelp-xsl | Jun 21, 2025 | Jun 14, 2025 |
| Oracle_linux | — | Upgrade yelp-develUpgrade yelpUpgrade yelp-xslUpgrade yelp-libs | May 19, 2025 | Apr 3, 2025 |
| Redhat_linux | — | Upgrade yelp-libsUpgrade yelp-develUpgrade yelp-debuginfoUpgrade yelp-debugsourceUpgrade yelpNo solution existsUpgrade yelp-xslUpgrade yelp-libs-debuginfo | May 6, 2025 | Apr 3, 2025 |
| Rocky_linux | — | Upgrade yelp-libsUpgrade yelp-develUpgrade yelp-debuginfoUpgrade yelp-libs-debuginfoUpgrade yelp-debugsourceUpgrade yelp | Jul 31, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade libyelp0Upgrade yelp-develUpgrade yelpUpgrade yelp-langUpgrade yelp-xsl | Jun 30, 2025 | Apr 3, 2025 |
| Ubuntu | — | Upgrade yelp-xslUpgrade yelp | Apr 24, 2025 | Apr 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub