Skip to content

OpenRefine 3.8.4

Choose a tag to compare

@wetneb wetneb released this 24 Oct 06:50
· 1036 commits to master since this release

This release fixes a collection of important vulnerabilities in OpenRefine. We encourage users to upgrade swiftly.

To continue using the Google Drive and Google Sheets integration, users need to obtain their own application credentials from the Google API Console.

Note: the vulnerability fixes were originally released as 3.8.3 but that version is dysfunctional due to human errors in the release process. The description of the vulnerabilities is included again here for visibility.

Vulnerabilities in OpenRefine

Vulnerabilities in bundled extensions

Vulnerabilities in Butterfly (web framework used in OpenRefine)

Special thanks to @wandernauta for the hard work that went into analyzing and reporting those vulnerabilities responsibly and to @tfmorris for reviewing mitigations.