CVE-2023-22949

MEDIUM

TigerGraph Enterprise Free Edition 3.x - Cleartext Storage of Sensitive Information in GSQL Access Logs

Title source: llm
STIX 2.1

Description

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.

References (2)

Core 2

Scores

CVSS v3 4.9
EPSS 0.0042
EPSS Percentile 33.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (2)
tigergraph/cloud
tigergraph/tigergraph_enterprise 3.7.0 (2 CPE variants)
Published Apr 14, 2023
Tracked Since Feb 18, 2026