Skip to content
OpenRefineGHSA-qfwq-6jh6-8xx4

OpenRefine has a path traversal in LoadLanguageCommand

High7.1CVE-2024-49760 · Published Oct 24, 2024 · updated Nov 6, 2024

The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. When doing so, it does not check that the resulting path is in the expected directory, which means that this command could be exploited to read other JSON files on the file system. The command should be patched by checking that the normalized path is in the expected directory.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.openrefine:openrefine
Maven
< 3.8.33.8.3
Details and references

More OpenRefine advisories

All OpenRefine
Advisory
OpenRefine leaks Google API credentials in releases
HighOct 24, 2024
OpenRefine: cross-site scripting
Medium5.9Oct 24, 2024
OpenRefine has a reflected cross-site scripting vulnerability (XSS) from POST request in ExportRowsCommand
High8.1Oct 24, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.