TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-312 |
Mon, 22 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:topquadrant:topbraid_edg:7.1.3:*:*:*:*:*:*:* |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Feb 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets. |
| CPEs | ||
| Vendors & Products |
Topquadrant
Topquadrant topbraid Edg |
|
| References |
|
Fri, 27 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. |
| Title | TopQuadrant TopBraid EDG password manager stores external credentials insecurely | |
| First Time appeared |
Topquadrant
Topquadrant topbraid Edg |
|
| CPEs | cpe:2.3:a:topquadrant:topbraid_edg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Topquadrant
Topquadrant topbraid Edg |
|
| Metrics |
cvssV3_1
|
Fri, 27 Sep 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. | |
| Weaknesses | CWE-257 | |
| References |
|
|
Status: PUBLISHED
Assigner: cisa-cg
Published: 2024-09-27T15:56:11.980Z
Updated: 2025-10-02T14:09:27.993Z
Reserved: 2024-09-05T23:12:56.519Z
Link: CVE-2024-45744
Updated: 2024-09-27T17:44:29.242Z
Status : Modified
Published: 2024-09-27T16:15:04.940
Modified: 2025-10-02T15:15:52.620
Link: CVE-2024-45744
No data.