A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2025-04-03 14:15
Updated : 2025-08-12 21:15
NVD link : CVE-2025-3155
Mitre link : CVE-2025-3155
CVE.ORG link : CVE-2025-3155
JSON object : View
Products Affected
redhat
- enterprise_linux_for_power_little_endian
- codeready_linux_builder_for_power_little_endian_eus
- codeready_linux_builder_for_ibm_z_systems
- codeready_linux_builder_for_arm64_eus
- enterprise_linux_for_ibm_z_systems
- codeready_linux_builder_for_power_little_endian
- codeready_linux_builder_for_arm64
- enterprise_linux_server_aus
- codeready_linux_builder_for_ibm_z_systems_eus
- codeready_linux_builder
- enterprise_linux_eus
- enterprise_linux_for_power_little_endian_eus
- enterprise_linux_server_tus
- enterprise_linux_for_arm_64
- enterprise_linux
- enterprise_linux_update_services_for_sap_solutions
- enterprise_linux_for_ibm_z_systems_eus
- enterprise_linux_for_arm_64_eus
- codeready_linux_builder_for_eus
gnome
- yelp
debian
- debian_linux
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
