Bug 2418576 (CVE-2025-13947)
| Summary: | CVE-2025-13947 webkit: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | iamleot+rhbugzilla |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2418579, 2418580, 2418581 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-12-03 09:07:24 UTC
Are there any further details? Which versions are affected? Was it reported upstream? Can you please add such details as references too when filling CVEs? Thanks! This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:22789 https://access.redhat.com/errata/RHSA-2025:22789 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:22790 https://access.redhat.com/errata/RHSA-2025:22790 (In reply to Leonardo Taccari from comment #2) > Are there any further details? Which versions are affected? Was it reported > upstream? > > Can you please add such details as references too when filling CVEs? > > Thanks! JFTR, this is part of <https://webkitgtk.org/security/WSA-2025-0009.html> and it was fixed upstream in version 2.50.3. It would be nice if upstream WSA can be added as a reference too. |