Improper identity propagation allowing data source impersonation¶
Information¶
Advisory ID: DSA-2025-009
CVSS Base Score: 8.8
CVSS String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity: High
CWE classification: CWE-639
Summary¶
In Dataiku DSS before 14.2.3, improper handling of variables could allow an attacker to forge the identity used for connecting to data sources.
Affected Products¶
Dataiku DSS before 14.2.3
Fix¶
Dataiku 14.2.3 has been made available to customers to remediate this issue