CVE-2022-41401: SSRF
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41401?
CVE-2022-41401 is a Server-Side Request Forgery (SSRF) vulnerability in OpenRefine <= v3.5.2.
What is the severity of CVE-2022-41401?
CVE-2022-41401 has a severity rating of medium (6.5).
How does CVE-2022-41401 affect OpenRefine?
CVE-2022-41401 allows unauthorized users to exploit OpenRefine, potentially leading to unauthorized access to internal resources and sensitive file disclosure.
How do I fix CVE-2022-41401?
To fix CVE-2022-41401, upgrade to OpenRefine version 3.6.0 or newer.
What is Server-Side Request Forgery (SSRF)?
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests from the server to other internal or external resources.