CVE-2021-27225

In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataiku:data_science_studio:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-03-01 01:15

Updated : 2024-02-04 21:23


NVD link : CVE-2021-27225

Mitre link : CVE-2021-27225

CVE.ORG link : CVE-2021-27225


JSON object : View

Products Affected

dataiku

  • data_science_studio
CWE
CWE-863

Incorrect Authorization