漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
Vulnerability Description
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
保护机制失效
Vulnerability Title
GNOME yelp 处理逻辑错误漏洞
Vulnerability Description
GNOME yelp是GNOME基金会开源的一个文档浏览工具。 GNOME yelp存在处理逻辑错误漏洞,该漏洞源于yelp-xsl提供的Content Security Policy实现过于宽松,可能导致恶意Flatpak应用程序通过OpenURI门户打开特制帮助内容,并通过在结构化SVG文档中嵌入不受信任的CSS样式表绕过沙箱隔离,允许Yelp评估本地XML包含并通过远程CSS资源请求泄露任意用户可读的主机文件,导致敏感信息未经授权泄露。以下版本受到影响:Red Hat Enterprise Linu
CVSS Information
N/A
Vulnerability Type
N/A