CVE-2024-49760
- EPSS 0.39%
- Veröffentlicht 24.10.2024 22:15:04
- Zuletzt bearbeitet 06.11.2024 15:01:01
OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in v...
CVE-2024-47882
- EPSS 0.12%
- Veröffentlicht 24.10.2024 21:15:13
- Zuletzt bearbeitet 28.10.2024 14:26:11
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injection into the...
CVE-2024-47878
- EPSS 0.09%
- Veröffentlicht 24.10.2024 21:15:12
- Zuletzt bearbeitet 30.10.2024 18:01:44
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag in the output, so without escaping. An attacker cou...
CVE-2024-47879
- EPSS 0.1%
- Veröffentlicht 24.10.2024 21:15:12
- Zuletzt bearbeitet 04.12.2024 17:21:35
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-controlled e...
CVE-2024-47880
- EPSS 0.1%
- Veröffentlicht 24.10.2024 21:15:12
- Zuletzt bearbeitet 30.10.2024 17:42:42
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An ...
CVE-2024-47881
- EPSS 0.29%
- Veröffentlicht 24.10.2024 21:15:12
- Zuletzt bearbeitet 28.10.2024 14:14:02
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker...
CVE-2024-23833
- EPSS 1.33%
- Veröffentlicht 12.02.2024 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:58:31
OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read files on the host filesystem. Due ...
CVE-2023-41886
- EPSS 4.95%
- Veröffentlicht 15.09.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:21:51
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a file on a server. Version 3.7.5 fixes this issue.
CVE-2023-41887
- EPSS 62.61%
- Veröffentlicht 15.09.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:21:51
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this issue.
CVE-2022-41401
- EPSS 5%
- Veröffentlicht 04.08.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:23:09
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.