CVE Vulnerabilities

CVE-2023-22949

Cleartext Storage of Sensitive Information

Published: Apr 14, 2023 | Modified: Feb 07, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Cloud Tigergraph - (including) - (including)
Tigergraph_enterprise Tigergraph 3.7.0 (including) 3.7.0 (including)

Potential Mitigations

References