[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8)
TigerGraph Community Edition 4.2.4 default credentials and GSQL file write enable unauthenticated SSH command execution.
0day Rubbish publicly disclosed a CVSS 9.8 issue in TigerGraph Community Edition 4.2.4 combining shipped default credentials (CWE-798) with a GSQL TO_CSV arbitrary file write. The chain yields SSH command execution as the tigergraph service user (uid 1001), which owns the engine, graph data, catalog, and configuration. The advisory treats the issue as reachable without a separately created account. No CVE identifier is given in the post.