CVE-2023-28482

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 14, 2023
Updated: Aug 21, 2023
CWE ID 434

Summary

CVE-2023-28482 is a vulnerability affecting Tigergraph Enterprise 3.7.0. This issue allows any user with permissions to upload data on a single TigerGraph instance to access data uploaded by other users, regardless of their permissions. Multiple graphs hosted on the instance can be impacted, potentially leading to a breach of confidential data. The TigerGraph platform does not offer adequate protection for data confidentiality on the remote server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share