An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-13T00:00:00
Updated: 2024-08-02T10:20:31.379Z
Reserved: 2023-01-11T00:00:00
Link: CVE-2023-22948
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-13T19:15:08.120
Modified: 2024-11-21T07:45:42.093
Link: CVE-2023-22948
Redhat
No data.