CVE-2018-19859

OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
openrefineopenrefine
1.0
openrefineopenrefine
1.0:a1
openrefineopenrefine
1.0:a2
openrefineopenrefine
1.0:a3
openrefineopenrefine
1.0:a4
openrefineopenrefine
1.0:b1
openrefineopenrefine
1.0.1
openrefineopenrefine
1.0.2
openrefineopenrefine
1.0.3
openrefineopenrefine
1.0.5
openrefineopenrefine
1.0.6
openrefineopenrefine
1.0.7
openrefineopenrefine
1.1
openrefineopenrefine
2.0
openrefineopenrefine
2.1
openrefineopenrefine
2.1:rc1
openrefineopenrefine
2.5
openrefineopenrefine
2.5:rc1
openrefineopenrefine
2.5:rc3
openrefineopenrefine
2.6:alpha1
openrefineopenrefine
2.6:alpha2
openrefineopenrefine
2.6:beta1
openrefineopenrefine
2.6:rc1
openrefineopenrefine
2.6:rc2
openrefineopenrefine
2.7
openrefineopenrefine
2.7:rc1
openrefineopenrefine
2.7:rc2
openrefineopenrefine
2.8
openrefineopenrefine
3.0
openrefineopenrefine
3.0:beta
openrefineopenrefine
3.0:rc1
openrefineopenrefine
3.1
openrefineopenrefine
3.1:beta
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openrefine
bookworm
3.6.2-2+deb12u2
fixed
sid
3.7.8-1
fixed
trixie
3.7.8-1
fixed