PYSEC-2022-43064

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pytigergraph/PYSEC-2022-43064.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2022-43064
Aliases
  • CVE-2022-30331
Published
2022-09-05T16:15:00Z
Modified
2023-11-07T21:41:59.538771Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected."

References

Affected packages

PyPI / pytigergraph

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.0.0.5
0.0.2
0.0.3
0.0.4
0.0.4.5
0.0.4.6
0.0.4.7
0.0.4.7.1
0.0.4.7.2
0.0.4.7.3
0.0.4.7.4
0.0.4.7.5
0.0.4.7.6
0.0.5
0.0.5.1
0.0.5.2
0.0.5.3
0.0.5.4
0.0.5.5
0.0.5.6
0.0.5.7
0.0.5.8
0.0.6.0
0.0.6.1
0.0.6.2
0.0.6.3
0.0.6.4
0.0.6.5
0.0.6.6
0.0.6.7
0.0.6.8
0.0.6.9
0.0.7
0.0.8
0.0.8.1
0.0.8.2
0.0.8.4
0.0.8.5
0.0.9
0.0.9.1
0.0.9.2
0.0.9.3
0.0.9.4
0.0.9.5
0.0.9.6.2
0.0.9.6.3
0.0.9.6.4
0.0.9.6.5
0.0.9.6.6
0.0.9.6.7
0.0.9.6.8
0.0.9.6.9
0.0.9.7.1
0.0.9.7.2
0.0.9.7.3
0.0.9.7.4
0.0.9.7.5
0.0.9.7.6
0.0.9.7.7
0.0.9.7.8
0.0.9.7.9
0.0.9.8.0
0.0.9.8.1
0.0.9.8.2
0.0.9.8.3
0.0.9.8.4
0.0.9.8.5
0.0.9.8.6
0.0.9.8.7
0.0.9.8.8
0.0.9.8.9
0.0.9.9.0
0.0.9.9.1
0.0.9.9.2
0.9
0.9.1
0.9.2

1.*

1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.5