Image: exploit-db.com · rights & removal
[webapps] TigerGraph_Community_Edition 4.2.4
Reporting by Exploit DatabaseRead the original at exploit-db.com
Executive Summary
Facts Only
* TigerGraph Community Edition 4.2.4 permits a remote code-execution chain against the database host.
* The GUI administration port (14240) accepts default credentials: tigergraph:tigergraph.
* A specific GSQL query, `CREATE QUERY (FILE f, STRING c) { PRINT c TOCSV f; }`, allows unrestricted write to the FILE parameter without path validation.
* REST++ on port 9000 runs with `RESTPP.Factory.EnableAuth = False`, allowing unauthenticated file writes via a GET request.
* An unauthenticated GET request to `/query//?f=&c=` can write an arbitrary file in the context of this mechanism.
* The attacker can plant an SSH public key into `/home/tigergraph/.ssh/authorizedkeys`.
* SSH daemon is started with `OpenSSH default PubkeyAuthentication=yes`.
* SSH logon as `tigergraph@` allows command execution.
* The resulting user identity for command execution is the `tigergraph` user (UID 1001), not root.
Full Take
From the original · Exploit Database
Title: TigerGraph_Community_Edition 4.2.4 - arbitrary file write Author: 0day Rubbish Research Team Contact: disclosure@0day-rubbish.com Type: remote Platform: Linux TigerGraph Community Edition 4.2.4 -- default credentials + arbitrary file write -> SSH RCE Vulnerability summary: TigerGraph Community Edition 4.2.4 in its default configuration permits a remote code-execution chain against the…Read the full story at exploit-db.com
Sentinel — Human
This text reads like a detailed technical proof-of-concept or exploit write-up, exhibiting high domain specificity and procedural depth consistent with expert security research, likely human-authored.
