Vulnerabilities
Vulnerable Software
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-01-09
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-03-01
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
CVSS Score
5.4
EPSS Score
0.001
Published
2021-03-01
Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.
CVSS Score
8.1
EPSS Score
0.003
Published
2020-09-14
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
CVSS Score
5.3
EPSS Score
0.005
Published
2018-05-28


Contact Us

Shodan ® - All rights reserved