Описание
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
A flaw was found in nltk. A local attacker can exploit a symlink-based vulnerability in the IPIPANCorpusReader methods. By placing a symbolic link in the corpus root directory and invoking specific methods, an attacker can bypass security validation and read arbitrary files accessible to the process. This could lead to unauthorized information disclosure.
Отчет
The nltk library is vulnerable to information disclosure, allowing an attacker with local access and low privileges to read arbitrary files. This occurs if an attacker can place a symlink within the nltk corpus root directory, bypassing path validation and enabling access to sensitive data with the permissions of the running process.
Меры по смягчению последствий
To mitigate this vulnerability, restrict write access to the IPIPANCorpusReader corpus root directory. Ensure that only trusted users or processes have permissions to create or modify files within this directory. This prevents an attacker from placing malicious symlinks that could lead to arbitrary file disclosure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Not affected | ||
| Lightspeed Core | lightspeed-core/lightspeed-stack-rhel9 | Not affected | ||
| Lightspeed Core | lightspeed-core/rag-tool-cpu-rhel9 | Not affected | ||
| Lightspeed Core | lightspeed-core/rag-tool-cuda-12.9-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-ocp-rag-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-service-api-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-chatbot-rhel8 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llama-stack-core-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ogx-core-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
nltk versions before 3.10.2 contain a symlink-based arbitrary file rea ...
EPSS
5.5 Medium
CVSS3