An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.
                
            References
                    | Link | Resource | 
|---|---|
| https://dev.tigergraph.com/forum/c/tg-community/announcements/35 | Vendor Advisory | 
| https://neo4j.com/security/cve-2023-22948/ | Exploit Third Party Advisory | 
| https://dev.tigergraph.com/forum/c/tg-community/announcements/35 | Vendor Advisory | 
| https://neo4j.com/security/cve-2023-22948/ | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2023-04-13 19:15
Updated : 2025-02-07 17:15
NVD link : CVE-2023-22948
Mitre link : CVE-2023-22948
CVE.ORG link : CVE-2023-22948
JSON object : View
Products Affected
                tigergraph
- tigergraph
CWE
                
                    
                        
                        CWE-311
                        
            Missing Encryption of Sensitive Data
