Cleartext storage of sensitive information in Scikit-learn - CVE-2024-5206
Published: August 13, 2024
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an error in TfidfVectorizer, which includes sensitive information such as tokens into the training data set. A local user can run the application with the default arguments except that we limit the vocabulary size and gain access to sensitive information.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Package Hub 15
openSUSE Leap
openEuler
Anolis OS
Python for Scientific Computing
Oracle Financial Services Compliance Studio
Maximo Application Suite - Monitor Component
Maximo Application Suite - Predict Component
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
python-scikit-learn
python3-scikit-learn
python3-scikit-learn-debuginfo
python-scikit-learn-debugsource
python3-scikit-learn-doc
IBM Maximo Application Suite - AI Broker
IBM Process Mining
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
How to mitigate CVE-2024-5206
Python for Scientific Computing - update to 4.2.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.26, 8.11.24, 9.0.16, 9.1.6
Maximo Application Suite - Predict Component - update to 9.0.3
python-scikit-learn - update to 0.20.4-5
python3-scikit-learn - update to 0.20.4-5
python3-scikit-learn-debuginfo - update to 0.23.2-150300.3.3.1
python3-scikit-learn - update to 0.23.2-150300.3.3.1
python-scikit-learn-debugsource - update to 0.23.2-150300.3.3.1
IBM Maximo Application Suite - AI Broker - update to 1.0.1
python3-scikit-learn-doc - update to 1.5.0-1
python3-scikit-learn - update to 1.5.0-1
IBM Process Mining - update to 1.15.0 IF001
watsonx Assistant Cartridge - update to 5.1.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Business Automation Workflow - update to 24.0.0-IF001
External References
Related Security Bulletins
- Information disclosure in scikit-learn
- Splunk Python for Scientific Computing update for third-party packages
- SUSE update for python-scikit-learn
- openEuler update for python-scikit-learn
- Cleartext storage of sensitive information in IBM Maximo Application Suite - AI Broker
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Process Mining
- IBM Maximo Application Suite - Predict Component update for scikit-learn
- Anolis OS update for python-scikit-learn
- Multiple vulnerabilities in Oracle Financial Services Compliance Studio
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for scikit-learn
- IBM Maximo Application Suite - Monitor Component update for scikit-learn's TfidfVectorizer