漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
Vulnerability Description
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and traversal segments when using the nltk: URL scheme. The unsafe-path regex check is performed before url2pathname() decodes the %xx sequences (a classic decode-after-check / TOCTOU-style flaw), allowing an attacker to bypass the protection documented in NLTK's SECURITY.md and read arbitrary files from the filesystem. While literal traversal strings such as ../../../etc/passwd are correctly blocked, encoded variants such as %2fetc%2fpasswd, %2e%2e%2f..., and ..%2f..%2f slip past the regex and are subsequently decoded into a real filesystem path. This vulnerability is fixed in 3.10.0-rc1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
NLTK 路径遍历漏洞
Vulnerability Description
NLTK是NLTK组织开源的一个自然语言工具包。用于支持自然语言处理的研究和开发。 NLTK 3.10.0-rc1之前版本存在路径遍历漏洞,该漏洞源于在nltk: URL方案下对URL编码路径分隔符和遍历段进行解码前检查(TOCTOU风格缺陷),导致路径遍历漏洞,允许攻击者绕过安全保护并读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A