Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gx8h-h4pj-j52p

Опубликовано: 14 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.

EPSS

Процентиль: 15%
0.00049
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 4.9
nvd
почти 3 года назад

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.

EPSS

Процентиль: 15%
0.00049
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-312