REDHAT-BUG-2357091: High severity Yelp Yelp vulnerability
Published Apr 3, 2025
·Updated
Yelp, the GNOME user help application, allows help documents to execute arbitrary JavaScript. A malicious help document may exfiltrate user files to a remote server.
Affected Software
2 affected components
Yelp Yelp
Gnome GNOME user help application
Event History
Apr 3, 2025
Data Sourced
via Red Hat·02:02 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2357091?
The severity of REDHAT-BUG-2357091 is critical due to the potential for arbitrary JavaScript execution leading to data exfiltration.
2
How do I fix REDHAT-BUG-2357091?
To fix REDHAT-BUG-2357091, update the Yelp application to the latest version that addresses this vulnerability.
3
Who is affected by REDHAT-BUG-2357091?
Users of the Yelp GNOME user help application are affected by REDHAT-BUG-2357091.
4
What kind of attack can REDHAT-BUG-2357091 facilitate?
REDHAT-BUG-2357091 can facilitate attacks that exfiltrate user files to a remote server via malicious help documents.
5
When was REDHAT-BUG-2357091 discovered?
REDHAT-BUG-2357091 was reported in early 2023 and has since been tracked for its potential impact.