CVE-2018-10732: Dataiku Data Science Studio
Medium severity, CVSS 5.3. EPSS: 1.6% chance of exploitation in the next 30 days.
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
Affected products
- Dataiku Data Science Studio: before 4.2.3 (fixed in 4.2.3)
Published 2018-05-28. Last modified 2026-06-17.