PT-2023-18790 · Tigergraph · Tigergraph Enterprise Free Edition

CVE-2023-22948

·

Publicado

2023-04-13

·

Atualizado

2023-05-04

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TigerGraph Enterprise Free Edition versions 3.x
Description The issue allows for unsecured read access to an SSH private key. Any code running as the tigergraph user can read the SSH private key, granting an attacker password-less SSH access to all machines in the TigerGraph cluster.
Recommendations For TigerGraph Enterprise Free Edition versions 3.x, restrict access to the SSH private key to prevent unauthorized read access. As a temporary workaround, consider restricting the privileges of the tigergraph user to minimize the risk of exploitation.

Exploit

Correção

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22948

Produtos afetados

Tigergraph Enterprise Free Edition