CVE-2021-27225

In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:dataiku:data_science_studio:*:*:*:*:*:*:*:*

Information

Published : 2021-02-28 17:15

Updated : 2021-03-05 12:09


NVD link : CVE-2021-27225

Mitre link : CVE-2021-27225


JSON object : View

CWE
CWE-863

Incorrect Authorization

Advertisement

dedicated server usa

Products Affected

dataiku

  • data_science_studio