VendorsDataikudata_science_studioall versions
Vulnerabilities

Dataiku Data Science Studio (DSS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-51717
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
Published 2024-01-09 · Modified
9.8EPSS 0.006
CVE-2020-8817
Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.
Published 2020-09-14 · Modified
8.1EPSS 0.009
CVE-2023-24045
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
Published 2023-03-01 · Modified
6.5EPSS 0.008
CVE-2021-27225
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
Published 2021-03-01 · Modified
5.5EPSS 0.005
CVE-2018-10732
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
Published 2018-05-28 · Modified
5.3EPSS 0.016