CVE-2022-41401
MEDIUMOpenRefine <3.5.2 - SSRF
Title source: llmDescription
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.
Exploits (1)
References (3)
Scores
CVSS v3
6.5
EPSS
0.0500
EPSS Percentile
89.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-918
Status
published
Products (2)
openrefine/openrefine
< 3.5.2
org.openrefine/main
0 - 3.6.0Maven
Published
Aug 04, 2023
Tracked Since
Feb 18, 2026