An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-14T00:00:00

Updated: 2024-08-02T10:20:31.395Z

Reserved: 2023-01-11T00:00:00

Link: CVE-2023-22949

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-14T14:15:10.723

Modified: 2023-04-24T19:32:02.000

Link: CVE-2023-22949

cve-icon Redhat

No data.