Exposure of sensitive User information to other users

Information

  • Advisory ID: DSA-2026-013

  • CVSS Base Score: 4.3

  • CVSS String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

  • Severity: Medium

  • CWE classification: CWE-200

Summary

In Dataiku DSS between 14.4.0 inclusive and 14.7.5 exclusive, and in Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive, a user could access the encrypted version of other users’ secrets.

Affected Products

  • Dataiku DSS between 14.4.0 inclusive and 14.7.5 exclusive

  • Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive

Fix

Dataiku 14.7.5 and 15.0.2 have been made available to customers to remediate this issue.