OpenRefine是一款基于Java的开源工具。该产品主要用于加载数据、分析数据和清理数据等。 OpenRefine 3.8.3版本之前存在代码注入漏洞,该漏洞源于preview-expression命令缺乏跨站请求伪造保护。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenRefine | OpenRefine | < 3.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-47883 | 9.1 CRITICAL | Butterfly has path/URL confusion in resource handling leading to multiple weaknesses |
| CVE-2024-47878 | 8.1 HIGH | Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt) |
| CVE-2024-47880 | 8.1 HIGH | OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportR |
| CVE-2024-47881 | 8.1 HIGH | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE) |
| CVE-2024-49760 | 7.1 HIGH | OpenRefine has a path traversal in LoadLanguageCommand |
| CVE-2024-47882 | 5.9 MEDIUM | OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on impor |
No comments yet