Dataiku develops a data science and analytics platform where disclosures cluster around authentication, authorization, and data-exposure issues spanning sensitive-information exposure, improper credential handling, and file-upload validation. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dataiku over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51717CRITICAL Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. | Jan 9, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-8817HIGH Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata. | Sep 14, 2020 | 8.1 | 26 | NO | NO |
CVE-2023-24045MEDIUM In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request. | Mar 1, 2023 | 6.5 | 21 | NO | NO |
CVE-2021-27225MEDIUM In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects | Mar 1, 2021 | 5.4 | 20 | NO | NO |
CVE-2018-10732MEDIUM The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility. | May 28, 2018 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dataiku.
Media articles that mention a CVE ID that affects a product developed by Dataiku — matched by CVE ID, not by vendor name.