The vendor explicitly states that these products are not affected by this CVE.
- exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence
- lightspeed-core/lightspeed-stack-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-cpu-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-cuda-12.9-rhel9 as a component of Lightspeed Core
- openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-ocp-rag-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ogx-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-ta-lmes-job-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in NLTK. This path traversal vulnerability, located in the FramenetCorpusReader and NKJPCorpusReader components, allows an attacker to read arbitrary XML files accessible to the application. This can be achieved by supplying unsafe selectors or poisoned index state, exploiting methods such as `frame_by_name`, `doc`, `lu`, and `header` with specially crafted parameters. The primary consequence is information disclosure.
- Remediation
- No remediation text is recorded.
