org.openrefine:openrefine
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.openrefine:openrefinepage 1 of 1
- CVE-2024-47880HIGHCVSS 8.1EG 8.1✓ Fixed in 3.8.32024-10-24
vulnerable: 3.6-beta1 ... 3.8.2 (15 versions)
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the r…
- CVE-2024-47882MEDIUMCVSS 5.9EG 5.9✓ Fixed in 3.8.32024-10-24
vulnerable: 3.6-beta1 ... 3.8.2 (15 versions)
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injecti…
- CVE-2024-49760HIGHCVSS 7.1EG 7.1✓ Fixed in 3.8.32024-10-24
vulnerable: 3.6-beta1 ... 3.8.2 (15 versions)
OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when do…
Check whether org.openrefine:openrefine is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.openrefine:openrefine CVEs against the assets you own.
Start Free Scan →