USN-8627-1: Yelp vulnerability
It was discovered that Yelp incorrectly handled certain crafted help
documents due to an overly permissive Content Security Policy. An
attacker could trick a user into opening a specially crafted document,
possibly resulting in the disclosure of sensitive information.