{"id":"GHSA-q7mc-fc87-v7w7","summary":"OpenRefine Server-Side Request Forgery vulnerability","details":"OpenRefine \u003c= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.","aliases":["CVE-2022-41401"],"modified":"2024-02-16T08:13:33.069738Z","published":"2023-08-04T18:30:39Z","database_specific":{"github_reviewed_at":"2023-08-04T21:25:42Z","nvd_published_at":"2023-08-04T17:15:09Z","cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41401"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/commit/8cb2fec45dd90fda8ed9608c691f6bb8ed721cd2"},{"type":"PACKAGE","url":"https://github.com/OpenRefine/OpenRefine"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/blob/30d6edb7b6586623bda09456c797c35983fb80ff/main/tests/server/src/com/google/refine/importing/ImportingUtilitiesTests.java#L180"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/blob/cb55cdfdf6f9ca916839778dc847cce803688998/main/src/com/google/refine/importing/ImportingUtilities.java#L103"},{"type":"WEB","url":"https://github.com/ixSly/CVE-2022-41401"}],"affected":[{"package":{"name":"org.openrefine:main","ecosystem":"Maven","purl":"pkg:maven/org.openrefine/main"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.0"}]}],"versions":["3.6-beta1","3.6-beta2","3.6-rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-q7mc-fc87-v7w7/GHSA-q7mc-fc87-v7w7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}