Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Dataiku Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24045 1 Dataiku 1 Data Science Studio 2023-03-09 N/A 6.5 MEDIUM
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
CVE-2021-27225 1 Dataiku 1 Data Science Studio 2021-03-05 5.5 MEDIUM 5.4 MEDIUM
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
CVE-2020-8817 1 Dataiku 1 Data Science Studio 2020-09-18 5.5 MEDIUM 8.1 HIGH
Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.
CVE-2018-10732 1 Dataiku 1 Data Science Studio 2018-07-02 5.0 MEDIUM 5.3 MEDIUM
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.