OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openrefine
Openrefine openrefine |
|
| CPEs | cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openrefine
Openrefine openrefine |
|
| Metrics |
ssvc
|
Thu, 24 Oct 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue. | |
| Title | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-24T20:31:09.314Z
Updated: 2024-10-25T19:07:07.083Z
Reserved: 2024-10-04T16:00:09.631Z
Link: CVE-2024-47881
Updated: 2024-10-25T19:07:01.278Z
Status : Analyzed
Published: 2024-10-24T21:15:12.957
Modified: 2024-10-28T14:14:02.157
Link: CVE-2024-47881
No data.