PT-2024-31743 · Topquadrant · Topbraid Edg
Donald Macary
·
Published
2024-09-27
·
Updated
2025-10-02
·
CVE-2024-45744
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
TopBraid EDG versions prior to 7.3
TopBraid EDG versions 7.1.3
Description:
TopBraid EDG stores external credentials insecurely, allowing an authenticated attacker with file system access to read
edg-setup.properties and obtain the secret to decrypt external passwords stored in edg-vault.properties. This could enable the attacker to gain unauthorized access to sensitive information.Recommendations:
For versions prior to 7.3, consider upgrading to version 7.3 or later, which introduces HashiCorp Vault integration that does not store external passwords locally.
For version 7.1.3, consider upgrading to version 7.3 or later to address the insecure storage of external credentials.
For version 8.3.0, heed the warning about using plain text secrets and take appropriate measures to secure external credentials.
Fix
Insufficiently Protected Credentials
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Topbraid Edg