Vulnerabilities > CVE-2021-27225 - Incorrect Authorization vulnerability in Dataiku Data Science Studio

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
dataiku
CWE-863

Summary

In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.

Vulnerable Configurations

Part Description Count
Application
Dataiku
118

Common Weakness Enumeration (CWE)