CVE-2021-27225

In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataiku:data_science_studio:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:57

Type Values Removed Values Added
References () https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.html - Vendor Advisory () https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.html - Vendor Advisory
References () https://doc.dataiku.com/dss/latest/ - Vendor Advisory () https://doc.dataiku.com/dss/latest/ - Vendor Advisory

Information

Published : 2021-03-01 01:15

Updated : 2024-11-21 05:57


NVD link : CVE-2021-27225

Mitre link : CVE-2021-27225

CVE.ORG link : CVE-2021-27225


JSON object : View

Products Affected

dataiku

  • data_science_studio
CWE
CWE-863

Incorrect Authorization