Description
An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration setting. GSQL queries that contain UDFs can bypass this configuration setting and, as a consequence, can write to any file location to which the administrative user has access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32153 | An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration setting. GSQL queries that contain UDFs can bypass this configuration setting and, as a consequence, can write to any file location to which the administrative user has access. |
References
| Link | Providers |
|---|---|
| https://neo4j.com/security/cve-2023-28483/ |
|
History
Wed, 09 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-09T16:18:52.391Z
Reserved: 2023-03-16T00:00:00.000Z
Link: CVE-2023-28483
Updated: 2024-08-02T12:38:25.449Z
Status : Modified
Published: 2023-08-14T19:15:10.567
Modified: 2024-11-21T07:55:11.890
Link: CVE-2023-28483
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD