{"api_version":"1","generated_at":"2026-07-23T14:46:26+00:00","cve":"CVE-2021-27225","urls":{"html":"https://cve.report/CVE-2021-27225","api":"https://cve.report/api/cve/CVE-2021-27225.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-27225","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-27225"},"summary":{"title":"CVE-2021-27225","description":"In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-03-01 01:15:00","updated_at":"2021-03-05 20:09:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.html","name":"https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Incorrect access control in Jupyter notebooks — Dataiku DSS 8.0 documentation","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://doc.dataiku.com/dss/latest/","name":"https://doc.dataiku.com/dss/latest/","refsource":"MISC","tags":["Vendor Advisory"],"title":"Data Science Studio — Data Science Studio 1.3.1 documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-27225","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27225","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"27225","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dataiku","cpe5":"data_science_studio","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"27225","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dataiku","cpe5":"data_science_studio","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-27225","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://doc.dataiku.com/dss/latest/","refsource":"MISC","name":"https://doc.dataiku.com/dss/latest/"},{"refsource":"CONFIRM","name":"https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.html","url":"https://doc.dataiku.com/dss/8.0/security/advisories/cve-2021-27225.html"}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AC:L/AV:N/A:N/C:L/I:L/PR:L/S:U/UI:N","version":"3.1"}}},"nvd":{"publishedDate":"2021-03-01 01:15:00","lastModifiedDate":"2021-03-05 20:09:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.5},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dataiku:data_science_studio:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"27225","Ordinal":"202316","Title":"CVE-2021-27225","CVE":"CVE-2021-27225","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"27225","Ordinal":"1","NoteData":"In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"27225","Ordinal":"2","NoteData":"2021-02-28","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"27225","Ordinal":"3","NoteData":"2021-02-28","Type":"Other","Title":"Modified"}]}}}