CVE-2019-3580: Path Traversal
Published Jan 3, 2019
·Updated
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
Affected Software
1 affected component
OpenRefine openrefine<=3.1
Event History
Jan 3, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-3580.
2
What is the severity level of CVE-2019-3580?
The severity level of CVE-2019-3580 is high with a severity value of 7.5.
3
What is the affected software of CVE-2019-3580?
The affected software of CVE-2019-3580 is OpenRefine up to and including version 3.1.
4
What is the description of CVE-2019-3580?
CVE-2019-3580 allows arbitrary file write in OpenRefine through 3.1 due to Directory Traversal during the import of a crafted project file.
5
Is there a reference link for CVE-2019-3580?
Yes, you can find the reference link for CVE-2019-3580 at https://github.com/OpenRefine/OpenRefine/issues/1927.