High severity8.8NVD Advisory· Published Sep 5, 2022· Updated Jun 17, 2026
CVE-2022-30331
CVE-2022-30331
Description
The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:tigergraph:tigergraph:3.6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:tigergraph:tigergraph:3.6.0:*:*:*:*:*:*:*
- (no CPE)range: =3.6.0
- TigerGraph/TigerGraphdescription
Patches
Vulnerability mechanics
References
3- docs.tigergraph.com/home/nvdProductVendor Advisory
- docs.tigergraph.com/home/cve-2022-30331nvdVendor Advisory
- neo4j.com/security/cve-2022-30331/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.