CVE-2018-10732: Dataiku Data Science Studio

Medium severity, CVSS 5.3. EPSS: 1.6% chance of exploitation in the next 30 days.

The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.

Affected products

  • Dataiku Data Science Studio: before 4.2.3 (fixed in 4.2.3)

Published 2018-05-28. Last modified 2026-06-17.