An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.
References
Link | Resource |
---|---|
https://dev.tigergraph.com/forum/c/tg-community/announcements/35 | Vendor Advisory |
https://neo4j.com/security/cve-2023-22948/ | Exploit Third Party Advisory |
https://dev.tigergraph.com/forum/c/tg-community/announcements/35 | Vendor Advisory |
https://neo4j.com/security/cve-2023-22948/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://dev.tigergraph.com/forum/c/tg-community/announcements/35 - Vendor Advisory | |
References | () https://neo4j.com/security/cve-2023-22948/ - Exploit, Third Party Advisory |
Information
Published : 2023-04-13 19:15
Updated : 2024-11-21 07:45
NVD link : CVE-2023-22948
Mitre link : CVE-2023-22948
CVE.ORG link : CVE-2023-22948
JSON object : View
Products Affected
tigergraph
- tigergraph
CWE
CWE-311
Missing Encryption of Sensitive Data