A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade yelp-develUpgrade yelpUpgrade yelp-xslUpgrade yelp-libs | May 20, 2025 | Apr 3, 2025 |
| Alpine Linux | — | Upgrade yelp-xslUpgrade yelp | Aug 8, 2025 | Apr 3, 2025 |
| Amazon Linux Ami 2 | — | Upgrade yelpUpgrade yelp-debuginfoUpgrade yelp-libsUpgrade yelp-xsl-develUpgrade yelp-xslUpgrade yelp-devel | May 30, 2025 | Apr 3, 2025 |
| Debian | — | Upgrade yelp-xslUpgrade yelp | May 15, 2025 | Apr 3, 2025 |
| Freebsd | — | Upgrade yelpUpgrade yelp-xsl | Jun 21, 2025 | Jun 14, 2025 |
| Oracle_linux | — | Upgrade yelp-libsUpgrade yelp-develUpgrade yelp-xslUpgrade yelp | May 19, 2025 | Apr 3, 2025 |
| Redhat_linux | — | No solution existsUpgrade yelp-xslUpgrade yelpUpgrade yelp-libs-debuginfoUpgrade yelp-libsUpgrade yelp-debugsourceUpgrade yelp-develUpgrade yelp-debuginfo | May 6, 2025 | Apr 3, 2025 |
| Rocky_linux | — | Upgrade yelpUpgrade yelp-debugsourceUpgrade yelp-libsUpgrade yelp-debuginfoUpgrade yelp-libs-debuginfoUpgrade yelp-devel | Jul 31, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade yelp-develUpgrade yelp-langUpgrade yelp-xslUpgrade yelpUpgrade libyelp0 | Jun 30, 2025 | Apr 3, 2025 |
| Ubuntu | — | Upgrade yelpUpgrade yelp-xsl | Apr 24, 2025 | Apr 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub