An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Link | Tags |
---|---|
https://dev.tigergraph.com/forum/c/tg-community/announcements/35 | vendor advisory |
https://neo4j.com/security/cve-2023-22950/ | third party advisory exploit |