Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28482

Опубликовано: 14 авг. 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tigergraph:tigergraph:3.7.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.5
github
больше 2 лет назад

An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-434