VulnerabilityModified
CVE-2021-27225
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
MEDIUM 5.4EPSS 0.52%
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.52% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- dataiku/data science studio
- Source
- cve@mitre.org
References
- https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.htmlVendor Advisory
- https://doc.dataiku.com/dss/latest/Vendor Advisory
- https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.htmlVendor Advisory
- https://doc.dataiku.com/dss/latest/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.