Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7mc-fc87-v7w7

Опубликовано: 04 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

OpenRefine Server-Side Request Forgery vulnerability

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

Пакеты

Наименование

org.openrefine:main

maven
Затронутые версииВерсия исправления

< 3.6.0

3.6.0

EPSS

Процентиль: 89%
0.05001
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

CVSS3: 6.5
nvd
больше 2 лет назад

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

CVSS3: 6.5
debian
больше 2 лет назад

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vul ...

EPSS

Процентиль: 89%
0.05001
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918