4.9
CVE-2023-22949
- EPSS 0.05%
- Veröffentlicht 14.04.2023 14:15:10
- Zuletzt bearbeitet 07.02.2025 22:15:11
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tigergraph ≫ Cloud Version-
Tigergraph ≫ Tigergraph Enterprise Version3.7.0 SwEditionfree SwPlatform-
Tigergraph ≫ Tigergraph Enterprise Version3.7.0 SwEditionfree SwPlatformdocker
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.161 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.