Search CVE reports


Toggle filters

1 – 10 of 12 results


CVE-2024-49760

Medium priority
Fixed

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`....

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release
Show less packages

CVE-2024-47883

Medium priority
Needs evaluation

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or...

1 affected package

openrefine-butterfly

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine-butterfly Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-47882

Medium priority
Fixed

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML...

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release
Show less packages

CVE-2024-47881

Medium priority
Fixed

OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration,...

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release
Show less packages

CVE-2024-47880

Medium priority
Fixed

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken...

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release
Show less packages

CVE-2024-47879

Medium priority
Fixed

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an...

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release
Show less packages

CVE-2024-47878

Medium priority
Fixed

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag in the output, so without...

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release
Show less packages

CVE-2024-23833

Medium priority

Some fixes available 3 of 4

OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read files on the...

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release Not in release Not in release
Show less packages

CVE-2023-41887

Medium priority

Some fixes available 2 of 4

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch...

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release Ignored Ignored
Show less packages

CVE-2023-41886

Medium priority

Some fixes available 2 of 4

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a file on a server. Version 3.7.5 fixes this issue.

1 affected package

openrefine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openrefine Fixed Fixed Not in release Ignored Ignored
Show less packages