GHSA-m88m-crr9-jvqq
OpenRefine vulnerable to zip slip in project import
Quick fix
GHSA-m88m-crr9-jvqq — org.openrefine:main: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.7.4</version> for org.openrefine:mainDetails
### Impact
A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution if a user can be convinced to import it.
### Patches
The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible.
### Workarounds
Only import OpenRefine projects from trusted sources.
### References
A similar [issue](https://github.com/OpenRefine/OpenRefine/issues/1840) existed in the Create Project feature ([CVE-2018-19859](https://nvd.nist.gov/vuln/detail/CVE-2018-19859)), which was fixed by PR [#1901](https://github.com/OpenRefine/OpenRefine/pull/1901).
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 3.7.4# pom.xml: bump <version>3.7.4</version> for org.openrefine:mainReferences
- https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-m88m-crr9-jvqq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-37476[ADVISORY]
- https://github.com/OpenRefine/OpenRefine/commit/e9c1e65d58b47aec8cd676bd5c07d97b002f205e[WEB]
- https://github.com/OpenRefine/OpenRefine[PACKAGE]
- https://github.com/OpenRefine/OpenRefine/releases/tag/3.7.4[WEB]
- https://www.sonarsource.com/blog/openrefine-zip-slip[WEB]