An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.
References
Link | Resource |
---|---|
https://dev.tigergraph.com/forum/c/tg-community/announcements/35 | Vendor Advisory |
https://neo4j.com/security/cve-2023-22948/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-04-13 19:15
Updated : 2024-02-28 20:13
NVD link : CVE-2023-22948
Mitre link : CVE-2023-22948
CVE.ORG link : CVE-2023-22948
JSON object : View
Products Affected
tigergraph
- tigergraph
CWE
CWE-311
Missing Encryption of Sensitive Data