Time-of-Check / Time-of-Use issue in UIF mechanism

Information

  • Advisory ID: DSA-2025-008

  • CVSS Base Score: 4.1

  • CVSS String: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N

  • Severity: Medium

  • CWE classification: CWE-367

Summary

In Dataiku DSS before 14.2.0, a TOCTOU vulnerability could allow Dataiku administrators to escalate privileges on the underlying Linux OS. Only administrators could leverage the issue.

Affected Products

  • Dataiku DSS before 14.2.0

Fix

Dataiku 14.2.0 have been made available to customers to remediate this issue