org.openrefine:database
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.openrefine:databasepage 1 of 1
- CVE-2023-41886HIGHCVSS 7.5EG 7.5✓ Fixed in 3.7.52023-09-15
vulnerable: 3.6-beta1 ... 3.7.2 (10 versions)
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a file on a server. Version 3.7.5 fixes this issue.
- CVE-2023-41887CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.7.52023-09-15
vulnerable: 3.6-beta1 ... 3.7.2 (10 versions)
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this is…
- CVE-2024-23833HIGHCVSS 7.5EG 7.5✓ Fixed in 3.7.82024-02-12
vulnerable: 3.6-beta1 ... 3.7.2 (10 versions)
OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read files on the host files…
- CVE-2024-47881HIGHCVSS 8.1EG 8.1✓ Fixed in 3.8.32024-10-24
vulnerable: 3.6-beta1 ... 3.8.2 (15 versions)
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling …
Check whether org.openrefine:database is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.openrefine:database CVEs against the assets you own.
Start Free Scan →