Openrefine

Openrefine

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 24.10.2024 22:15:04
  • Zuletzt bearbeitet 06.11.2024 15:01:01

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in v...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 24.10.2024 21:15:13
  • Zuletzt bearbeitet 28.10.2024 14:26:11

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injection into the...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 24.10.2024 21:15:12
  • Zuletzt bearbeitet 30.10.2024 18:01:44

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag in the output, so without escaping. An attacker cou...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 24.10.2024 21:15:12
  • Zuletzt bearbeitet 04.12.2024 17:21:35

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-controlled e...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 24.10.2024 21:15:12
  • Zuletzt bearbeitet 30.10.2024 17:42:42

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 24.10.2024 21:15:12
  • Zuletzt bearbeitet 28.10.2024 14:14:02

OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker...

Exploit
  • EPSS 1.33%
  • Veröffentlicht 12.02.2024 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:58:31

OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read files on the host filesystem. Due ...

Exploit
  • EPSS 4.95%
  • Veröffentlicht 15.09.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 08:21:51

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a file on a server. Version 3.7.5 fixes this issue.

Exploit
  • EPSS 62.61%
  • Veröffentlicht 15.09.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 08:21:51

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this issue.

Exploit
  • EPSS 5%
  • Veröffentlicht 04.08.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 07:23:09

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.