OpenRefine是一款基于Java的开源工具。该产品主要用于加载数据、分析数据和清理数据等。 OpenRefine 3.8.3版本之前存在路径遍历漏洞,该漏洞源于load-language命令的lang参数缺少检查,导致路径遍历
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenRefine | OpenRefine | < 3.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-47883 | 9.1 CRITICAL | Butterfly has path/URL confusion in resource handling leading to multiple weaknesses |
| CVE-2024-47878 | 8.1 HIGH | Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt) |
| CVE-2024-47880 | 8.1 HIGH | OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportR |
| CVE-2024-47881 | 8.1 HIGH | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE) |
| CVE-2024-47879 | 7.6 HIGH | OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site |
| CVE-2024-47882 | 5.9 MEDIUM | OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on impor |
No comments yet