Insufficient credentials protection¶
Information¶
Advisory ID: DSA-2026-014
CVSS Base Score: 7.7
CVSS String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Severity: High
CWE classification: CWE-522
Summary¶
In Dataiku DSS before 14.7.5, and in Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive, a user could decrypt information that DSS encrypts for storage. The encryption key itself was not exposed.
Affected Products¶
Dataiku DSS before 14.7.5
Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive
Fix¶
Dataiku 14.7.5 and 15.0.2 have been made available to customers to remediate this issue.