CVE-2023-22948
Summary
| CVE | CVE-2023-22948 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-13 19:15:00 UTC |
| Updated | 2023-05-04 13:32:00 UTC |
| Description | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tigergraph | Tigergraph | All | All | All | All |
| Application | Tigergraph | Tigergraph | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Unsecured SSH Credentials - Neo4j Graph Data Platform | MISC | neo4j.com | |
| Latest Announcements topics - TigerGraph | MISC | dev.tigergraph.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.