VDB
Sign up
MEDIUM5.5

GHSA-m88m-crr9-jvqq

OpenRefine vulnerable to zip slip in project import

Quick fix

GHSA-m88m-crr9-jvqq — org.openrefine:main: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.7.4</version> for org.openrefine:main

Details

### Impact

A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution if a user can be convinced to import it.

### Patches

The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible.

### Workarounds

Only import OpenRefine projects from trusted sources.

### References

A similar [issue](https://github.com/OpenRefine/OpenRefine/issues/1840) existed in the Create Project feature ([CVE-2018-19859](https://nvd.nist.gov/vuln/detail/CVE-2018-19859)), which was fixed by PR [#1901](https://github.com/OpenRefine/OpenRefine/pull/1901).

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.openrefine:main
Introduced in: 0Fixed in: 3.7.4
Fix# pom.xml: bump <version>3.7.4</version> for org.openrefine:main

References