The vendor explicitly states that these products are not affected by this CVE.
- exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence
- lightspeed-core/lightspeed-stack-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-cpu-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-cuda-12.9-rhel9 as a component of Lightspeed Core
- openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-ocp-rag-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ogx-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ta-lmes-job-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in nltk. A local attacker can exploit a symlink-based vulnerability in the IPIPANCorpusReader methods. By placing a symbolic link in the corpus root directory and invoking specific methods, an attacker can bypass security validation and read arbitrary files accessible to the process. This could lead to unauthorized information disclosure.
- Remediation
- No remediation text is recorded.
