Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2096 | OpenRefine vulnerable to zip slip in project import |
Github GHSA |
GHSA-m88m-crr9-jvqq | OpenRefine vulnerable to zip slip in project import |
Ubuntu USN |
USN-7260-1 | OpenRefine vulnerabilities |
Tue, 10 Jun 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources. | OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources. |
| References |
|
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-10T15:30:33.285Z
Reserved: 2023-07-06T13:01:36.999Z
Link: CVE-2023-37476
Updated: 2024-08-02T17:16:30.319Z
Status : Modified
Published: 2023-07-17T22:15:09.450
Modified: 2025-06-10T16:15:34.153
Link: CVE-2023-37476
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN