Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-37476
Disclosure Date: July 17, 2023 (last updated February 25, 2025)
OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources.
0
Attacker Value
Unknown
CVE-2019-3580
Disclosure Date: January 03, 2019 (last updated November 27, 2024)
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
0
Attacker Value
Unknown
CVE-2018-20157
Disclosure Date: December 15, 2018 (last updated November 27, 2024)
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.
0
Attacker Value
Unknown
CVE-2018-19859
Disclosure Date: December 05, 2018 (last updated November 27, 2024)
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
0