Directory Traversal Vulnerability in OpenRefine by Google
CVE-2019-3580

7.5HIGH

Key Information:

Vendor

Openrefine

Vendor
CVE Published:
3 January 2019

What is CVE-2019-3580?

OpenRefine versions up to 3.1 are susceptible to a directory traversal vulnerability that enables attackers to perform arbitrary file writes during the import of a specially crafted project file. This security flaw could potentially lead to unauthorized access to sensitive files on the system. It is essential for users of OpenRefine to apply necessary updates and patch their installations to mitigate any associated risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.