Vulnerability Description
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tigergraph | Tigergraph | >= 3.0, <= 3.7.0 |
Related Weaknesses (CWE)
References
- https://dev.tigergraph.com/forum/c/tg-community/announcements/35Vendor Advisory
- https://neo4j.com/security/cve-2023-22950/ExploitThird Party Advisory
- https://dev.tigergraph.com/forum/c/tg-community/announcements/35Vendor Advisory
- https://neo4j.com/security/cve-2023-22950/ExploitThird Party Advisory
FAQ
What is CVE-2023-22950?
CVE-2023-22950 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.
How severe is CVE-2023-22950?
CVE-2023-22950 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22950?
Check the references section above for vendor advisories and patch information. Affected products include: Tigergraph Tigergraph.