Описание
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the database extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-apps/jammy | released | 3.5.2-1ubuntu0.1~esm1 |
| esm-apps/noble | released | 3.7.7-1ubuntu0.1~esm1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | needed | |
| noble | needed | |
| oracular | released | 3.7.8-1ubuntu0.1 |
| plucky | not-affected | |
| questing | not-affected |
Показывать по
8.1 High
CVSS3
Связанные уязвимости
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue.
OpenRefine is a free, open source tool for working with messy data. St ...
OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
Уязвимость расширения database программного средства извлечения и очистки табличных данных OpenRefine, позволяющая нарушителю выполнить произвольный код
8.1 High
CVSS3