CVE-2024-49760 Information
Nov 01, 2024
cve
Description
OpenRefine is a free open source tool for working with messy data. The load-language command expects a lang parameter from which it constructs the path of the localization file to load of the form translations-$LANG.json. But when doing so in versions prior to 3.8.3 it does not check that the resulting path is in the expected directory which means that this command could be exploited to read other JSON files on the file system. Version 3.8.3 addresses this issue.
Reference
https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-qfwq-6jh6-8xx4 https://github.com/OpenRefine/OpenRefine/commit/24d084052dc55426fe460f2a17524fd18d28b20c
Share on: