First published: Thu Jan 03 2019(Updated: )
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openrefine Openrefine | <=3.1 | |
<=3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-3580.
The severity level of CVE-2019-3580 is high with a severity value of 7.5.
The affected software of CVE-2019-3580 is OpenRefine up to and including version 3.1.
CVE-2019-3580 allows arbitrary file write in OpenRefine through 3.1 due to Directory Traversal during the import of a crafted project file.
Yes, you can find the reference link for CVE-2019-3580 at https://github.com/OpenRefine/OpenRefine/issues/1927.