Lucene search

K

Data Science Studio Security Vulnerabilities

cve
cve

CVE-2018-10732

The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.

5.3CVSS

5.1AI Score

0.002EPSS

2018-05-28 05:29 PM
16
cve
cve

CVE-2020-8817

Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.

8.1CVSS

8AI Score

0.001EPSS

2020-09-14 02:15 PM
20
cve
cve

CVE-2021-27225

In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.

5.4CVSS

5.4AI Score

0.001EPSS

2021-03-01 01:15 AM
59
3
cve
cve

CVE-2023-24045

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

6.5CVSS

6.4AI Score

0.001EPSS

2023-03-01 01:15 AM
16
cve
cve

CVE-2023-51717

Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

9.8CVSS

9.4AI Score

0.001EPSS

2024-01-09 02:15 AM
7