Insufficient credentials protection

Information

  • Advisory ID: DSA-2026-014

  • CVSS Base Score: 7.7

  • CVSS String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

  • Severity: High

  • CWE classification: CWE-522

Summary

In Dataiku DSS before 14.7.5, and in Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive, a user could decrypt information that DSS encrypts for storage. The encryption key itself was not exposed.

Affected Products

  • Dataiku DSS before 14.7.5

  • Dataiku DSS between 15.0.0 inclusive and 15.0.2 exclusive

Fix

Dataiku 14.7.5 and 15.0.2 have been made available to customers to remediate this issue.