In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-03-01T00:24:18

Updated: 2021-03-01T00:24:18

Reserved: 2021-02-16T00:00:00


Link: CVE-2021-27225

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-03-01T01:15:12.467

Modified: 2021-03-05T20:09:38.807


Link: CVE-2021-27225

JSON object: View

cve-icon Redhat Information

No data.

CWE