SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-28482

The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server.

MEDIUM 6.5EPSS 0.66%

Does this matter?

Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.66% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
tigergraph/tigergraph
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.