Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2022-41401

Disclosure Date: August 04, 2023 (last updated February 25, 2025)
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.
Attacker Value
Unknown

CVE-2023-37476

Disclosure Date: July 17, 2023 (last updated February 25, 2025)
OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources.
Attacker Value
Unknown

CVE-2019-3580

Disclosure Date: January 03, 2019 (last updated November 27, 2024)
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
0
Attacker Value
Unknown

CVE-2018-20157

Disclosure Date: December 15, 2018 (last updated November 27, 2024)
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.
0
Attacker Value
Unknown

CVE-2018-19859

Disclosure Date: December 05, 2018 (last updated November 27, 2024)
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
0