8.8
CVE-2023-22951
- EPSS 0.11%
- Veröffentlicht 13.04.2023 20:15:08
- Zuletzt bearbeitet 07.02.2025 17:15:24
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tigergraph ≫ Cloud Version-
Tigergraph ≫ Tigergraph Enterprise Version3.7.0 SwEditionfree SwPlatform-
Tigergraph ≫ Tigergraph Enterprise Version3.7.0 SwEditionfree SwPlatformdocker
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.295 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.