Описание
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
Ссылки
- ExploitVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
7.1 High
CVSS3
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
NLTK before 3.9.3 fails to verify file integrity after downloading pac ...
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
EPSS
7.1 High
CVSS3
6.5 Medium
CVSS3