Dataiku / Data Science Studio
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-51717 | Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. | CRITICAL | 9.8 | Jan 9, 2024 |
| CVE-2023-24045 | In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download r… | MEDIUM | 6.5 | Mar 1, 2023 |
| CVE-2021-27225 | In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite… | MEDIUM | 5.4 | Mar 1, 2021 |
| CVE-2020-8817 | Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata. | HIGH | 8.1 | Sep 14, 2020 |
| CVE-2018-10732 | The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pi… | MEDIUM | 5.3 | May 28, 2018 |
Showing 1 to 5 of 5 CVEs