Vulnerabilities > Dataiku > Data Science Studio > 8.0.5

DATE CVE VULNERABILITY TITLE RISK
2024-01-09 CVE-2023-51717 Improper Authentication vulnerability in Dataiku Data Science Studio
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
network
low complexity
dataiku CWE-287
critical
9.8
2023-03-01 CVE-2023-24045 Unrestricted Upload of File with Dangerous Type vulnerability in Dataiku Data Science Studio
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
network
low complexity
dataiku CWE-434
6.5