ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28479
An issue was discovered in Tigergraph Enterprise 3.7.0.

An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain within every TigerGraph deployment. An attacker is able to compile new executables on each Tigergraph system and modify system and Tigergraph binaries.

NVD description · AI analysis pending
8.8<1% PoC
  • tigergraph tigergraph
CVE-2023-28483
+3 in the same advisory: …28481 …28482 …28480
An issue was discovered in Tigergraph Enterprise 3.7.0.

An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration setting. GSQL queries that contain UDFs can bypass this configuration setting and, as a consequence, can write to any file location to which the administrative user has access.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • tigergraph tigergraph
CVE-2023-22949
An issue was discovered in TigerGraph Enterprise Free Edition 3.x.

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.

NVD description · AI analysis pending
4.9<1% PoC
  • tigergraph cloud
  • tigergraph tigergraph enterprise
CVE-2023-22951
An issue was discovered in TigerGraph Enterprise Free Edition 3.x.

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.

NVD description · AI analysis pending
8.8<1% PoC
  • tigergraph cloud
  • tigergraph tigergraph enterprise
CVE-2023-22950
+1 in the same advisory: …22948
An issue was discovered in TigerGraph Enterprise Free Edition 3.x.

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • tigergraph tigergraph
CVE-2022-30331
The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation.

The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected."

NVD description · AI analysis pending
8.81%
  • tigergraph tigergraph