CVE-2024-47882 - CVE House
Back to Database
Status published Medium CVE-2024-47882

OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project

Vulnerability Description

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injection into the page if an attacker can reliably produce an error with an attacker-influenced message. It appears that the only way to reach this code in OpenRefine itself is for an attacker to somehow convince a victim to import a malicious file, which may be difficult. However, out-of-tree extensions may add their own calls to `respondWithErrorPage`. Version 3.8.3 has a fix for this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47882

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

OpenRefine
Vulnerable Versions:
< 3.8.3

Timeline

Official Publish: October 24th, 2024
Last Modified: October 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N

Weaknesses (CWE)