CVE-2023-22950

Severity CVSS v4.0:
Pending analysis
Type:
CWE-669 Incorrect Resource Transfer Between Spheres
Publication date:
13/04/2023
Last modified:
07/02/2025

Description

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tigergraph:tigergraph:*:*:*:*:cloud:*:*:* 3.0 (including) 3.7.0 (including)
cpe:2.3:a:tigergraph:tigergraph:*:*:*:*:enterprise_free:*:*:* 3.0 (including) 3.7.0 (including)