CVE-2023-22950
6.5MEDIUMAn issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.
Publicado: 4/13/2023Actualizado: 2/7/2025
Descripción
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.
Análisis IAImpulsado por IA
Productos Afectados
tigergraphtigergraph
tigergraphtigergraph
Referencias
- https://dev.tigergraph.com/forum/c/tg-community/announcements/35Vendor Advisory
- https://neo4j.com/security/cve-2023-22950/ExploitThird Party Advisory
- https://dev.tigergraph.com/forum/c/tg-community/announcements/35Vendor Advisory
- https://neo4j.com/security/cve-2023-22950/ExploitThird Party Advisory