CVE-2023-22948

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
13/04/2023
Last modified:
07/02/2025

Description

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tigergraph:tigergraph:*:*:*:*:cloud:*:*:* 3.0 (including) 3.7.0 (including)
cpe:2.3:a:tigergraph:tigergraph:*:*:*:*:enterprise_free:*:*:* 3.0 (including) 3.7.0 (including)