CVE-2023-24045 Information

Description

In Dataiku DSS 11.2.1 an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

Reference

https://dataiku.com https://gist.github.com/alert3/04e2d0a934001180104f846cfa00552b

Share on: