Exposure of sensitive User information to other users¶
Information¶
Advisory ID: DSA-2026-013
CVSS Base Score: 4.3
CVSS String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity: Medium
CWE classification: CWE-200
Summary¶
In Dataiku DSS between 14.4.0 inclusive and 14.7.5 exclusive, and in Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive, a user could access the encrypted version of other users’ secrets.
Affected Products¶
Dataiku DSS between 14.4.0 inclusive and 14.7.5 exclusive
Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive
Fix¶
Dataiku 14.7.5 and 15.0.2 have been made available to customers to remediate this issue.