Medium severity4.9NVD Advisory· Published Apr 14, 2023· Updated Jun 17, 2026
CVE-2023-22949
CVE-2023-22949
Description
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:tigergraph:cloud:-:*:*:*:*:*:*:*
cpe:2.3:a:tigergraph:tigergraph_enterprise:3.7.0:*:*:*:free:-:*:*+ 1 more
- cpe:2.3:a:tigergraph:tigergraph_enterprise:3.7.0:*:*:*:free:-:*:*
- cpe:2.3:a:tigergraph:tigergraph_enterprise:3.7.0:*:*:*:free:docker:*:*
- TigerGraph/TigerGraph Enterprise Free Editiondescription
- Range: 3.x
Patches
Vulnerability mechanics
References
2- neo4j.com/security/cve-2023-22949/nvdExploitThird Party Advisory
- dev.tigergraph.com/forum/c/tg-community/announcements/35nvdProduct
News mentions
0No linked articles in our index yet.