Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2024.0228
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2024-0228)
Resumen:The remote host is missing an update for the 'python-scikit-learn' package(s) announced via the MGASA-2024-0228 advisory.
Descripción:Summary:
The remote host is missing an update for the 'python-scikit-learn' package(s) announced via the MGASA-2024-0228 advisory.

Vulnerability Insight:
A sensitive data leakage vulnerability was identified in scikit-learn's
TfidfVectorizer, specifically in versions up to and including
1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises
from the unexpected storage of all tokens present in the training data
within the `stop_words_` attribute, rather than only storing the subset
of tokens required for the TF-IDF technique to function. This behavior
leads to the potential leakage of sensitive information, as the
`stop_words_` attribute could contain tokens that were meant to be
discarded and not stored, such as passwords or keys. The impact of this
vulnerability varies based on the nature of the data being processed by
the vectorizer.

Affected Software/OS:
'python-scikit-learn' package(s) on Mageia 9.

Solution:
Please install the updated package(s).

CVSS Score:
3.8

CVSS Vector:
AV:L/AC:H/Au:S/C:C/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2024-5206
https://github.com/scikit-learn/scikit-learn/commit/70ca21f106b603b611da73012c9ade7cd8e438b8
https://huntr.com/bounties/14bc0917-a85b-4106-a170-d09d5191517c
CopyrightCopyright (C) 2024 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.