An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.
History

Fri, 07 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-07T21:10:03.385Z

Reserved: 2023-01-11T00:00:00.000Z

Link: CVE-2023-22949

cve-icon Vulnrichment

Updated: 2024-08-02T10:20:31.395Z

cve-icon NVD

Status : Modified

Published: 2023-04-14T14:15:10.723

Modified: 2025-02-07T22:15:11.310

Link: CVE-2023-22949

cve-icon Redhat

No data.