VulnerabilityModified
CVE-2023-24045
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
MEDIUM 6.5EPSS 0.75%
Does this matter?
Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.
Description
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- dataiku/data science studio
- Source
- cve@mitre.org
References
- https://dataiku.comProduct
- https://gist.github.com/alert3/04e2d0a934001180104f846cfa00552bExploit, Third Party Advisory
- https://dataiku.comProduct
- https://gist.github.com/alert3/04e2d0a934001180104f846cfa00552bExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.