{"id":"UBUNTU-CVE-2024-5206","details":"A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data within the `stop_words_` attribute, rather than only storing the subset of tokens required for the TF-IDF technique to function. This behavior leads to the potential leakage of sensitive information, as the `stop_words_` attribute could contain tokens that were meant to be discarded and not stored, such as passwords or keys. The impact of this vulnerability varies based on the nature of the data being processed by the vectorizer.","modified":"2026-05-20T16:09:44.565033788Z","published":"2024-06-06T19:16:00Z","upstream":["CVE-2024-5206"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-5206"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-5206"},{"type":"REPORT","url":"https://huntr.com/bounties/14bc0917-a85b-4106-a170-d09d5191517c"},{"type":"REPORT","url":"https://github.com/scikit-learn/scikit-learn/commit/70ca21f106b603b611da73012c9ade7cd8e438b8"}],"affected":[{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.13.1-1","0.14.1-1","0.14.1-2"],"ecosystem_specific":{"binaries":[{"binary_name":"python-scikits-learn","binary_version":"0.14.1-2"},{"binary_version":"0.14.1-2","binary_name":"python-sklearn"},{"binary_version":"0.14.1-2","binary_name":"python-sklearn-lib"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}},{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.16.1-2","0.17.0-4"],"ecosystem_specific":{"binaries":[{"binary_name":"python-scikits-learn","binary_version":"0.17.0-4"},{"binary_version":"0.17.0-4","binary_name":"python-sklearn"},{"binary_name":"python-sklearn-lib","binary_version":"0.17.0-4"},{"binary_name":"python3-sklearn","binary_version":"0.17.0-4"},{"binary_name":"python3-sklearn-lib","binary_version":"0.17.0-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}},{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.19.0-1build1","0.19.1-1","0.19.1-2","0.19.1-3"],"ecosystem_specific":{"binaries":[{"binary_name":"python-scikits-learn","binary_version":"0.19.1-3"},{"binary_version":"0.19.1-3","binary_name":"python-sklearn"},{"binary_name":"python-sklearn-lib","binary_version":"0.19.1-3"},{"binary_name":"python3-sklearn","binary_version":"0.19.1-3"},{"binary_name":"python3-sklearn-lib","binary_version":"0.19.1-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}},{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.20.3+dfsg-0ubuntu2","0.20.3+dfsg-0ubuntu3","0.22.2.post1+dfsg-5"],"ecosystem_specific":{"binaries":[{"binary_version":"0.22.2.post1+dfsg-5","binary_name":"python3-sklearn"},{"binary_version":"0.22.2.post1+dfsg-5","binary_name":"python3-sklearn-lib"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}},{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.23.2-5ubuntu2","0.23.2-5ubuntu4","0.23.2-5ubuntu6"],"ecosystem_specific":{"binaries":[{"binary_version":"0.23.2-5ubuntu6","binary_name":"python3-sklearn"},{"binary_version":"0.23.2-5ubuntu6","binary_name":"python3-sklearn-lib"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}},{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.1+dfsg-1build1","1.2.1+dfsg-1build2","1.4.1.post1+dfsg-1","1.4.1.post1+dfsg-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.4.1.post1+dfsg-1build1","binary_name":"python3-sklearn"},{"binary_name":"python3-sklearn-lib","binary_version":"1.4.1.post1+dfsg-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}},{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.2+dfsg-8"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-sklearn","binary_version":"1.4.2+dfsg-8"},{"binary_name":"python3-sklearn-lib","binary_version":"1.4.2+dfsg-8"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}},{"package":{"name":"scikit-learn","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/scikit-learn?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.2+dfsg-8","1.7.2+dfsg-3ubuntu1","1.7.2+dfsg-4","1.7.2+dfsg-4build1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-sklearn","binary_version":"1.7.2+dfsg-4build1"},{"binary_name":"python3-sklearn-lib","binary_version":"1.7.2+dfsg-4build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5206.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}