An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-14T00:00:00
Updated: 2024-08-02T10:20:31.395Z
Reserved: 2023-01-11T00:00:00
Link: CVE-2023-22949
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-14T14:15:10.723
Modified: 2024-11-21T07:45:42.277
Link: CVE-2023-22949
Redhat
No data.