CVE-2024-47881

HIGH
Published Oct 24, 2024 Modified Oct 28, 2024 CWE-89

Description

OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue.

Is your site exposed to CVE-2024-47881?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.1
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Weakness Type (CWE)

CWE-89 SQL Injection

Affected Products

Vendor Product
openrefine openrefine

References

Frequently Asked Questions

What is CVE-2024-47881? +
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue. It has a CVSS v3.1 base score of 8.1 (HIGH).
How severe is CVE-2024-47881? +
CVE-2024-47881 has a CVSS v3.1 score of 8.1 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-47881? +
CVE-2024-47881 affects products from openrefine, specifically: openrefine. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-47881? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-47881 — free, no signup required.