CVE-2024-5206 is a sensitive data leakage vulnerability in scikit-learn's TfidfVectorizer, affecting versions up to 1.4.1.post1. The issue stems from the vectorizer unexpectedly storing all training data tokens in the stop_words_ attribute, potentially exposing sensitive information like passwords or keys that should have been discarded. Rated Medium severity with a CVSS score of 4.7, this vulnerability has a local attack vector and high confidentiality impact, though high attack complexity is required. The potential impact varies depending on the sensitivity of the data processed. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:scikit-learn:scikit-learn:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.