Vulnerabilities > Dataiku > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2023-24045 Unrestricted Upload of File with Dangerous Type vulnerability in Dataiku Data Science Studio
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
network
low complexity
dataiku CWE-434
6.5
2021-03-01 CVE-2021-27225 Incorrect Authorization vulnerability in Dataiku Data Science Studio
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
network
low complexity
dataiku CWE-863
5.4
2018-05-28 CVE-2018-10732 Information Exposure vulnerability in Dataiku Data Science Studio
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
network
low complexity
dataiku CWE-200
5.3