Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-41401

Опубликовано: 04 авг. 2023
Источник: debian
EPSS Низкий

Описание

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openrefinefixed3.6.1-1package

Примечания

  • https://github.com/ixSly/CVE-2022-41401

  • https://github.com/OpenRefine/OpenRefine/issues/4918

  • https://github.com/OpenRefine/OpenRefine/commit/8cb2fec45dd90fda8ed9608c691f6bb8ed721cd2 (3.6-beta1)

EPSS

Процентиль: 89%
0.05001
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

CVSS3: 6.5
nvd
больше 2 лет назад

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

CVSS3: 6.5
github
больше 2 лет назад

OpenRefine Server-Side Request Forgery vulnerability

EPSS

Процентиль: 89%
0.05001
Низкий