OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openrefine
Openrefine openrefine |
|
CPEs | cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openrefine
Openrefine openrefine |
|
Metrics |
ssvc
|
Thu, 24 Oct 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue. | |
Title | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE) | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-24T20:31:09.314Z
Updated: 2024-10-25T19:07:07.083Z
Reserved: 2024-10-04T16:00:09.631Z
Link: CVE-2024-47881
Vulnrichment
Updated: 2024-10-25T19:07:01.278Z
NVD
Status : Analyzed
Published: 2024-10-24T21:15:12.957
Modified: 2024-10-28T14:14:02.157
Link: CVE-2024-47881
Redhat
No data.