SCA: security update for org.openrefine:openrefine (GHSA-79jv-5226-783f)

high Tenable Cloud Security Plugin ID 411968

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-
rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type
header also taken from the request. An attacker could lead a user to a malicious page that submits a form
POST that contains embedded JavaScript code. This code would then be included in the response, along with
an attacker-controlled `Content-Type` header, and so potentially executed in the victim's browser as if it
was part of OpenRefine. The attacker-provided code can do anything the user can do, including deleting
projects, retrieving database passwords, or executing arbitrary Jython or Closure expressions, if those
extensions are also present. The attacker must know a valid project ID of a project that contains at least
one row. Version 3.8.3 fixes the issue. (CVE-2024-47880)

See Also

https://github.com/advisories/GHSA-79jv-5226-783f

Plugin Details

Severity: High

ID: 411968

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:N

CVSS Score Source: CVE-2024-47880

CVSS v3

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 6.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.6

Threat Score: 7.3

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/24/2024

Vulnerability Publication Date: 10/24/2024

Reference Information

CVE: CVE-2024-47880