OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.
References
Configurations
History
08 Aug 2023, 20:32
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/ixSly/CVE-2022-41401 - Exploit | |
References | (MISC) https://github.com/OpenRefine/OpenRefine/blob/cb55cdfdf6f9ca916839778dc847cce803688998/main/src/com/google/refine/importing/ImportingUtilities.java#L103 - Third Party Advisory | |
References | (MISC) https://github.com/OpenRefine/OpenRefine/blob/30d6edb7b6586623bda09456c797c35983fb80ff/main/tests/server/src/com/google/refine/importing/ImportingUtilitiesTests.java#L180 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CPE | cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:* | |
CWE | CWE-918 |
04 Aug 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-04 17:15
Updated : 2024-02-05 00:01
NVD link : CVE-2022-41401
Mitre link : CVE-2022-41401
CVE.ORG link : CVE-2022-41401
JSON object : View
Products Affected
openrefine
- openrefine
CWE
CWE-918
Server-Side Request Forgery (SSRF)