An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an attacker to obtain password-less SSH key access by using their own SSH key.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-08-14T00:00:00

Updated: 2024-08-02T12:38:25.370Z

Reserved: 2023-03-16T00:00:00

Link: CVE-2023-28481

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-08-14T19:15:10.413

Modified: 2023-08-21T17:18:27.813

Link: CVE-2023-28481

cve-icon Redhat

No data.