CVE-2023-24045: Dataiku Data Science Studio
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
Affected products
- Dataiku Data Science Studio: before 11.3.2 (fixed in 11.3.2)
Published 2023-03-01. Last modified 2026-06-17.