VYPR
Medium severity4.9NVD Advisory· Published Apr 13, 2023· Updated Jun 17, 2026

CVE-2023-22948

CVE-2023-22948

Description

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:tigergraph:tigergraph:*:*:*:*:cloud:*:*:*+ 1 more
    • cpe:2.3:a:tigergraph:tigergraph:*:*:*:*:cloud:*:*:*range: >=3.0,<=3.7.0
    • cpe:2.3:a:tigergraph:tigergraph:*:*:*:*:enterprise_free:*:*:*range: >=3.0,<=3.7.0
  • TigerGraph/Enterprise Free Editiondescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.