A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2025-04-03 14:15
Updated : 2025-08-12 21:15
NVD link : CVE-2025-3155
Mitre link : CVE-2025-3155
CVE.ORG link : CVE-2025-3155
JSON object : View
Products Affected
redhat
- enterprise_linux
- codeready_linux_builder_for_arm64
- codeready_linux_builder_for_power_little_endian
- enterprise_linux_eus
- enterprise_linux_for_power_little_endian
- enterprise_linux_for_arm_64
- codeready_linux_builder_for_arm64_eus
- enterprise_linux_for_arm_64_eus
- codeready_linux_builder_for_power_little_endian_eus
- codeready_linux_builder_for_eus
- codeready_linux_builder
- codeready_linux_builder_for_ibm_z_systems_eus
- enterprise_linux_server_tus
- enterprise_linux_for_power_little_endian_eus
- enterprise_linux_update_services_for_sap_solutions
- enterprise_linux_for_ibm_z_systems_eus
- enterprise_linux_server_aus
- codeready_linux_builder_for_ibm_z_systems
- enterprise_linux_for_ibm_z_systems
debian
- debian_linux
gnome
- yelp
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
