[MAVEN:GHSA-Q7MC-FC87-V7W7] OpenRefine Server-Side Request Forgery vulnerability

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

Package Affected Version
pkg:maven/org.openrefine/main < 3.6.0
Package Fixed Version
pkg:maven/org.openrefine/main = 3.6.0
ID
MAVEN:GHSA-Q7MC-FC87-V7W7
Severity
moderate
URL
https://github.com/advisories/GHSA-q7mc-fc87-v7w7
Published
2023-08-04T18:30:39
(13 months ago)
Modified
2023-11-10T05:01:36
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.openrefine/main org.openrefine main < 3.6.0
Fixed pkg:maven/org.openrefine/main org.openrefine main = 3.6.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...