Skip to main content

Vendor archive

openrefine CVEs

Beta · best-effort

15 CVEs tagged to vendor openrefine2 Critical, 9 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2024-49760

Published Oct 24, 2024

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47883

Published Oct 24, 2024

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-47882

Published Oct 24, 2024

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exce…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47881

Published Oct 24, 2024

OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extensio…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47880

Published Oct 24, 2024

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the reques…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47879

Published Oct 24, 2024

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47878

Published Oct 24, 2024

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23833

Published Feb 12, 2024

OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41887

Published Sep 15, 2023

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-41886

Published Sep 15, 2023

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41401

Published Aug 4, 2023

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized acces…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37476

Published Jul 17, 2023

OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the contex…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3580

Published Jan 3, 2019

OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20157

Published Dec 15, 2018

The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19859

Published Dec 5, 2018

OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1