4
CVSSv2

CVE-2018-19859

Published: 05/12/2018 Updated: 28/03/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

OpenRefine prior to 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openrefine openrefine 3.0

openrefine openrefine 2.7

openrefine openrefine 2.6

openrefine openrefine 1.0.5

openrefine openrefine 1.0.7

openrefine openrefine 2.0

openrefine openrefine 2.5

openrefine openrefine 1.0

openrefine openrefine 2.8

openrefine openrefine 3.1

openrefine openrefine 2.1

openrefine openrefine 1.0.1

openrefine openrefine 1.0.2

openrefine openrefine 1.0.3

openrefine openrefine 1.0.6

openrefine openrefine 1.1

Github Repositories

CVE-2018-19859 Remote Code Execution Proof of Concept

CVE-2018-19859 - RCE Proof of Concept This repository contains a proof of concept for Remote Code Execution (RCE) against OpenRefine < 31-beta By exploiting a directory traversal vulnerability inside of the Create Project functionality, CVE-2018-19859, a malicious user can upload a custom Java extension to gain code execution This proof of concept contains a simple Ja