High
CVSS 7.5
Overview
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.
The data import functionality in OpenRefine through 3.1 allows an XML External E...
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.
This vulnerability is rated 🟠 HIGH.
Recommended actions: