Dataiku
Dataiku Data Science Studio: vulnerabilidades y CVE
Dataiku Data Science Studio tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-51717 | Crítica (9.8) | 0.61% | — | 9 ene 2024 | Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. |
| CVE-2023-24045 | Media (6.5) | 0.75% | — | 1 mar 2023 | In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request. |
| CVE-2021-27225 | Media (5.4) | 0.53% | — | 1 mar 2021 | In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access. |
| CVE-2020-8817 | Alta (8.1) | 0.89% | — | 14 sept 2020 | Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata. |
| CVE-2018-10732 | Media (5.3) | 1.6% | — | 28 may 2018 | The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility. |