PT-2023-5893 · Unknown+2 · Openrefine+2

Stefan-Schiller-Sonarsource

·

Published

2023-07-17

·

Updated

2025-02-10

·

CVE-2023-37476

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenRefine versions prior to 3.7.4
Description The issue is related to a Zip Slip vulnerability in OpenRefine, which can be exploited by a specially crafted malicious OpenRefine project tar file. This can lead to arbitrary code execution in the context of the OpenRefine process if a user imports the malicious file.
Recommendations For OpenRefine versions prior to 3.7.4, update to OpenRefine 3.7.4 as soon as possible. For users unable to upgrade, only import OpenRefine projects from trusted sources. As a temporary workaround, consider restricting the import of OpenRefine projects to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-06589
CVE-2023-37476
GHSA-M88M-CRR9-JVQQ
USN-7260-1

Affected Products

Linuxmint
Openrefine
Ubuntu