TigerGraph develops a graph database platform deployed across analytics and enterprise data-integration use cases, with its vulnerability surface centered on the core TigerGraph product and its cloud and enterprise variants. The recurring weakness classes—including unrestricted file uploads, authorization bypass through user-controlled keys, cleartext storage of sensitive information, and improper input validation—reflect the authentication, data-handling, and file-management demands of a database platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tigergraph over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30331HIGH The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can ex | Sep 5, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-22951HIGH An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. | Apr 13, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-28479HIGH An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain within every TigerGraph deployment. An attacker is able to com | Aug 15, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-28483HIGH An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations | Aug 14, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-28481HIGH An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SS | Aug 14, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-22950MEDIUM An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arb | Apr 13, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-28482MEDIUM An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform | Aug 14, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-28480MEDIUM An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functional | Aug 14, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-22949MEDIUM An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple | Apr 14, 2023 | 4.9 | 19 | NO | NO |
CVE-2023-22948MEDIUM An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read t | Apr 13, 2023 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tigergraph.
Media articles that mention a CVE ID that affects a product developed by Tigergraph — matched by CVE ID, not by vendor name.