CVE-2023-24045

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
01/03/2023
Last modified:
10/03/2025

Description

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dataiku:data_science_studio:*:*:*:*:*:*:*:* 11.3.2 (excluding)