Dataiku REST-API by default the software, allows anonymous access to functionality that allows an attacker to know valid users.
# CVE-2018-10732
Exploit-DB publication at: No disclosure!
# Dataiku vendor Patch and Credits:
https://doc.dataiku.com/dss/latest/release_notes/4.2.html#security

# Author
Alex Hernandez aka <em><a href="https://twitter.com/_alt3kx_" rel="nofollow">(@\_alt3kx\_)</a></em>
登录后查看神龙缓存的 POC 文件快照
登录查看