8.8
CVE-2023-22951
- EPSS 0.83%
- Veröffentlicht 13.04.2023 20:15:08
- Zuletzt bearbeitet 07.02.2025 17:15:24
- Erkennungen
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tigergraph ≫ Cloud Version -
Tigergraph ≫ Tigergraph Enterprise Version 3.7.0 SwEdition free SwPlatform -
Tigergraph ≫ Tigergraph Enterprise Version 3.7.0 SwEdition free SwPlatform docker
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.83% | 0.526 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
https://dev.tigergraph.com/forum/c/tg-community/announcements/35
https://neo4j.com/security/cve-2023-22951/