In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://dataiku.com | product |
https://gist.github.com/alert3/04e2d0a934001180104f846cfa00552b | third party advisory exploit |