An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-14T00:00:00

Updated: 2023-04-14T00:00:00

Reserved: 2023-01-11T00:00:00


Link: CVE-2023-22949

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-04-14T14:15:10.723

Modified: 2023-04-24T19:32:02.000


Link: CVE-2023-22949

JSON object: View

cve-icon Redhat Information

No data.

CWE