
Dataiku REST-API by default the software, allows anonymous access to functionality that allows an attacker to know valid users.
Exploit-DB publication at: No disclosure!
https://doc.dataiku.com/dss/latest/release_notes/4.2.html#security

Alex Hernandez aka (@_alt3kx_)