Описание
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.0.6 (исключая)
cpe:2.3:a:dataiku:data_science_studio:*:*:*:*:*:*:*:*
EPSS
Процентиль: 33%
0.00132
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-863
Связанные уязвимости
github
больше 3 лет назад
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
EPSS
Процентиль: 33%
0.00132
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-863