Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-37476

Опубликовано: 17 июл. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

esm-apps/jammy

released

3.5.2-1ubuntu0.1~esm1
esm-apps/noble

released

3.7.7-1ubuntu0.1~esm1
esm-infra/focal

DNE

focal

DNE

jammy

needed

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 31%
0.00116
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources.

CVSS3: 5.5
debian
больше 2 лет назад

OpenRefine is a free, open source tool for data processing. A carefull ...

CVSS3: 5.5
github
больше 2 лет назад

OpenRefine vulnerable to zip slip in project import

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость программного средства извлечения и очистки табличных данных OpenRefine, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 31%
0.00116
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2023-37476