UBUNTU-CVE-2023-41886
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-41886
UBUNTU-CVE-2023-41886
Summary:
Details: OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a file on a server. Version 3.7.5 fixes this issue.
References: https://ubuntu.com/security/CVE-2023-41886, https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-qqh2-wvmv-h72m, https://github.com/OpenRefine/OpenRefine/commit/2de1439f5be63d9d0e89bbacbd24fa28c8c3e29d, https://github.com/OpenRefine/OpenRefine/commit/693fde606d4b5b78b16391c29d110389eb605511, https://www.cve.org/CVERecord?id=CVE-2023-41886, https://ubuntu.com/security/notices/USN-7260-1
Affected packages
Package
Name: openrefine
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/jammy
Affected ranges
Type: ECOSYSTEM
Events:
