PT-2024-31743 · Topquadrant · Topbraid Edg

Donald Macary

·

Published

2024-09-27

·

Updated

2025-10-02

·

CVE-2024-45744

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: TopBraid EDG versions prior to 7.3 TopBraid EDG versions 7.1.3
Description: TopBraid EDG stores external credentials insecurely, allowing an authenticated attacker with file system access to read edg-setup.properties and obtain the secret to decrypt external passwords stored in edg-vault.properties. This could enable the attacker to gain unauthorized access to sensitive information.
Recommendations: For versions prior to 7.3, consider upgrading to version 7.3 or later, which introduces HashiCorp Vault integration that does not store external passwords locally. For version 7.1.3, consider upgrading to version 7.3 or later to address the insecure storage of external credentials. For version 8.3.0, heed the warning about using plain text secrets and take appropriate measures to secure external credentials.

Fix

Insufficiently Protected Credentials

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-45744

Affected Products

Topbraid Edg