OpenRefine是一款基于Java的开源工具。该产品主要用于加载数据、分析数据和清理数据等。 OpenRefine 3.8.3版本之前存在安全漏洞,该漏洞源于内置的“Something went error!”错误页面包含异常消息和异常回溯,但不转义 HTML 标记。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenRefine | OpenRefine | < 3.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47883 | 9.1 CRITICAL | Butterfly has path/URL confusion in resource handling leading to multiple weaknesses |
| CVE-2024-47878 | 8.1 HIGH | Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt) |
| CVE-2024-47880 | 8.1 HIGH | OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportR |
| CVE-2024-47881 | 8.1 HIGH | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE) |
| CVE-2024-47879 | 7.6 HIGH | OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site |
| CVE-2024-49760 | 7.1 HIGH | OpenRefine has a path traversal in LoadLanguageCommand |
No comments yet