Skip to content

Instantly share code, notes, and snippets.

@alert3
Created February 27, 2023 19:42
Show Gist options
  • Save alert3/04e2d0a934001180104f846cfa00552b to your computer and use it in GitHub Desktop.
Save alert3/04e2d0a934001180104f846cfa00552b to your computer and use it in GitHub Desktop.
DataIku DSS < 11.3.2 - Broken Authorization
This is a description of Broken Object Level Authorization (BOLA) vulnerability found in DataIku DSS < 11.3.2
@alert3
Copy link
Author

alert3 commented Feb 27, 2023

Product

DataIku DSS before 11.3.2

Author

Amin Rawah

CVE ID

CVE-2023-24045

Description

A malicious user with normal privilege can download other DataIku users’ files under the myfile section which includes user config and other resources. This can be achieved by specifying the targeted username on the query string path to get his/her files.

PoC

image001

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment