scikit-learn CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

scikit-learn vulnerability overview

Aggregates CVE and security vulnerability intelligence across all scikit-learn-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk denial of service, with potential vendor impact application crash and vendor impact information disclosure across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-5206 A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data within the `stop_words_` attribute, rather than only storing the subset of tokens required for the TF-IDF technique to function. This behavior leads to the potential leakage of sensitive information, as the `stop_words_` at [email protected] 4.7 0.19% 2024-06-06 2024-11-21
CVE-2020-28975 svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute. [email protected] 7.5 3.43% 2020-11-21 2024-11-21
CVE-2020-13092 scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the joblib.load() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner [email protected] 9.8 2.65% 2020-05-15 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence