漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Server-Side Request Forgery (SSRF) in nltk/nltk
Vulnerability Description
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Python's `ipaddress` module does not classify such addresses as `is_private` or `is_global`, and the current guard only checks `is_private` and a few explicit categories. An attacker who can influence a URL passed to NLTK's network-loading helpers can exploit this vulnerability to make a strict-mode application send requests to shared-address-space hosts, potentially exposing non-public infrastructure reachable from the application host. The impact is limited to SSRF-style confidentiality exposure, with no code execution claimed.
CVSS Information
N/A
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
NLTK 服务端请求伪造漏洞
Vulnerability Description
NLTK是NLTK组织开源的一个自然语言处理工具包。 NLTK 3.9.4版本存在服务端请求伪造漏洞,该漏洞源于nltk.pathsec.validate_network_url()函数未能拒绝RFC 6598共享地址空间(100.64.0.0/10)中的IP地址,可能导致攻击者利用传递给NLTK网络加载助手的URL使严格模式应用程序向共享地址空间主机发送请求,造成信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A