logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-22949

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-22949

Description:
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.
Last updated date:
04/24/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/24/2023
Reference url to background

https://neo4j.com/security/cve-2023-22949/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy