Логотип exploitDog
bind:CVE-2024-49760
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-49760

Количество 4

Количество 4

ubuntu логотип

CVE-2024-49760

больше 1 года назад

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versions prior to 3.8.3, it does not check that the resulting path is in the expected directory, which means that this command could be exploited to read other JSON files on the file system. Version 3.8.3 addresses this issue.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2024-49760

больше 1 года назад

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versions prior to 3.8.3, it does not check that the resulting path is in the expected directory, which means that this command could be exploited to read other JSON files on the file system. Version 3.8.3 addresses this issue.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2024-49760

больше 1 года назад

OpenRefine is a free, open source tool for working with messy data. Th ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-qfwq-6jh6-8xx4

больше 1 года назад

OpenRefine has a path traversal in LoadLanguageCommand

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-49760

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versions prior to 3.8.3, it does not check that the resulting path is in the expected directory, which means that this command could be exploited to read other JSON files on the file system. Version 3.8.3 addresses this issue.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-49760

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versions prior to 3.8.3, it does not check that the resulting path is in the expected directory, which means that this command could be exploited to read other JSON files on the file system. Version 3.8.3 addresses this issue.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-49760

OpenRefine is a free, open source tool for working with messy data. Th ...

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-qfwq-6jh6-8xx4

OpenRefine has a path traversal in LoadLanguageCommand

CVSS3: 7.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу