CVE-2021-27225
Summary
| CVE | CVE-2021-27225 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-01 01:15:00 UTC |
| Updated | 2021-03-05 20:09:00 UTC |
| Description | In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dataiku | Data Science Studio | All | All | All | All |
| Application | Dataiku | Data Science Studio | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Incorrect access control in Jupyter notebooks — Dataiku DSS 8.0 documentation | CONFIRM | doc.dataiku.com | Vendor Advisory |
| Data Science Studio — Data Science Studio 1.3.1 documentation | MISC | doc.dataiku.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.