OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p3r5-x3hr-gpg5 | OpenRefine Remote Code execution in project import with mysql jdbc url attack |
Ubuntu USN |
USN-7260-1 | OpenRefine vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-25T18:55:03.906Z
Reserved: 2023-09-04T16:31:48.224Z
Link: CVE-2023-41887
Updated: 2024-08-02T19:09:49.411Z
Status : Modified
Published: 2023-09-15T21:15:11.407
Modified: 2024-11-21T08:21:51.357
Link: CVE-2023-41887
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA
Ubuntu USN