penRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag in the output, so without escaping. An attacker could lead or redirect a user to a crafted URL containing JavaScript code, which would then cause that code to be executed in the victim's browser as if it was part of OpenRefine. Version 3.8.3 fixes this issue.
| Link | Resource |
|---|---|
| https://github.com/OpenRefine/OpenRefine/commit/10bf0874d67f1018a58b3732332d76b840192fea | Patch |
| https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-pw3x-c5vp-mfc3 | Exploit Third Party Advisory |
30 Oct 2024, 18:01
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| References | () https://github.com/OpenRefine/OpenRefine/commit/10bf0874d67f1018a58b3732332d76b840192fea - Patch | |
| References | () https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-pw3x-c5vp-mfc3 - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:* | |
| First Time |
Openrefine
Openrefine openrefine |
25 Oct 2024, 12:56
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
24 Oct 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-10-24 21:15
Updated : 2024-10-30 18:01
NVD link : CVE-2024-47878
Mitre link : CVE-2024-47878
CVE.ORG link : CVE-2024-47878
JSON object : View
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')