本頁列出影響 dataiku data_science_studio 的已公開 CVE 漏洞(透過 NVD CPE 關聯)。每列包含嚴重程度評分、摘要與發布日期,便於識別與分析安全議題。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2023-51717 | Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. | [email protected] | 9.8 | 0.07% | 2024-01-09 | 2025-06-16 |
| CVE-2023-24045 | In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request. | [email protected] | 6.5 | 0.34% | 2023-03-01 | 2025-03-10 |
| CVE-2021-27225 | In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access. | [email protected] | 5.4 | 0.13% | 2021-03-01 | 2024-11-21 |
| CVE-2020-8817 | Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata. | [email protected] | 8.1 | 0.32% | 2020-09-14 | 2024-11-21 |
| CVE-2018-10732 | The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility. | [email protected] | 5.3 | 0.50% | 2018-05-28 | 2024-11-21 |