scikit-learn@1.5.0rc1 vulnerabilities

A set of python modules for machine learning and data mining

  • latest version

    1.6.1

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the scikit-learn package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Storage of Sensitive Data in a Mechanism without Access Control

    scikit-learn is a Python module for machine learning built on top of SciPy and is distributed under the 3-Clause BSD license.

    Affected versions of this package are vulnerable to Storage of Sensitive Data in a Mechanism without Access Control due to the unexpected storage of all tokens present in the training data within the stop_words_ attribute. An attacker can access sensitive information, such as passwords or keys, by exploiting this behavior.

    How to fix Storage of Sensitive Data in a Mechanism without Access Control?

    Upgrade scikit-learn to version 1.5.0 or higher.

    [,1.5.0)