TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Feb 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets. |
CPEs | ||
Vendors & Products |
Topquadrant
Topquadrant topbraid Edg |
|
References |
|
Fri, 27 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 27 Sep 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. |
Title | TopQuadrant TopBraid EDG password manager stores external credentials insecurely | |
First Time appeared |
Topquadrant
Topquadrant topbraid Edg |
|
CPEs | cpe:2.3:a:topquadrant:topbraid_edg:*:*:*:*:*:*:*:* | |
Vendors & Products |
Topquadrant
Topquadrant topbraid Edg |
|
Metrics |
cvssV3_1
|
Fri, 27 Sep 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. | |
Weaknesses | CWE-257 | |
References |
|
|

Status: PUBLISHED
Assigner: cisa-cg
Published: 2024-09-27T15:56:11.980Z
Updated: 2025-03-11T17:50:17.447Z
Reserved: 2024-09-05T23:12:56.519Z
Link: CVE-2024-45744

Updated: 2024-09-27T17:44:29.242Z

Status : Awaiting Analysis
Published: 2024-09-27T16:15:04.940
Modified: 2025-02-18T19:15:16.240
Link: CVE-2024-45744

No data.