First published: Thu Apr 03 2025(Updated: )
Yelp, the GNOME user help application, allows help documents to execute arbitrary JavaScript. A malicious help document may exfiltrate user files to a remote server.
Affected Software | Affected Version | How to fix |
---|---|---|
Yelp | ||
GNOME User Help Application |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2357091 is critical due to the potential for arbitrary JavaScript execution leading to data exfiltration.
To fix REDHAT-BUG-2357091, update the Yelp application to the latest version that addresses this vulnerability.
Users of the Yelp GNOME user help application are affected by REDHAT-BUG-2357091.
REDHAT-BUG-2357091 can facilitate attacks that exfiltrate user files to a remote server via malicious help documents.
REDHAT-BUG-2357091 was reported in early 2023 and has since been tracked for its potential impact.