VulnerabilityModified
CVE-2023-28482
The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server.
MEDIUM 6.5EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.66% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- tigergraph/tigergraph
- Source
- cve@mitre.org
References
- https://neo4j.com/security/cve-2023-28482/Exploit, Third Party Advisory
- https://neo4j.com/security/cve-2023-28482/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.