Description
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
Remediation
References
https://github.com/OpenRefine/OpenRefine/issues/1927
Related Vulnerabilities
CVE-2023-34840 Vulnerability in npm package angular-ui-notification
CVE-2021-44138 Vulnerability in maven package com.caucho:resin
CVE-2019-12041 Vulnerability in maven package org.webjars.npm:remarkable
CVE-2020-14061 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-34371 Vulnerability in maven package org.neo4j:neo4j