Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28479 | An issue was discovered in Tigergraph Enterprise 3.7.0. An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain within every TigerGraph deployment. An attacker is able to compile new executables on each Tigergraph system and modify system and Tigergraph binaries. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-28483 | An issue was discovered in Tigergraph Enterprise 3.7.0. An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration setting. GSQL queries that contain UDFs can bypass this configuration setting and, as a consequence, can write to any file location to which the administrative user has access. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2023-22949 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords. NVD description · AI analysis pending | 4.9 | <1% | PoC |
| — | |
| CVE-2023-22951 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-22950 +1 in the same advisory: …22948 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2022-30331 | The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected." NVD description · AI analysis pending | 8.8 | 1% |
| — |