Description
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
Remediation
References
https://github.com/OpenRefine/OpenRefine/issues/1927
Related Vulnerabilities
CVE-2018-19838 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2020-7782 Vulnerability in npm package spritesheet-js
CVE-2019-17495 Vulnerability in maven package org.webjars:swagger-ui
CVE-2021-33040 Vulnerability in npm package epubjs
CVE-2017-12615 Vulnerability in maven package org.apache.tomcat:tomcat-catalina