{"id":"CVE-2022-41401","details":"OpenRefine \u003c= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.","aliases":["GHSA-q7mc-fc87-v7w7"],"modified":"2026-08-12T03:51:16.126849085Z","published":"2023-08-04T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41401.json"},"references":[{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/blob/30d6edb7b6586623bda09456c797c35983fb80ff/main/tests/server/src/com/google/refine/importing/ImportingUtilitiesTests.java#L180"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/blob/cb55cdfdf6f9ca916839778dc847cce803688998/main/src/com/google/refine/importing/ImportingUtilities.java#L103"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41401.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41401"},{"type":"PACKAGE","url":"https://github.com/ixSly/CVE-2022-41401"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openrefine/openrefine","events":[{"introduced":"0"},{"last_affected":"e3efd4ec270bfa07a2575efa6ece11b6e269d105"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.5.2"}]}}],"versions":["3.5.2","3.5.1","3.5.0","3.5-beta2","3.5-beta1","3.4-beta","3.3","3.3-rc1","3.3-beta","3.2","3.2-beta","3.1","3.1-beta","3.0","3.0-rc.1","3.0-beta","2.8","2.7","2.7-rc.2","2.7-rc.1","2.6-rc.2","v2.6-rc1","2.6-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41401.json"}}],"schema_version":"1.9.0"}