TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 02 Oct 2025 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-312

Mon, 22 Sep 2025 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-522
CPEs cpe:2.3:a:topquadrant:topbraid_edg:7.1.3:*:*:*:*:*:*:*

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00087}

epss

{'score': 0.00109}


Tue, 18 Feb 2025 19:00:00 +0000

Type Values Removed Values Added
Description TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.
CPEs cpe:2.3:a:topquadrant:topbraid_edg:*:*:*:*:*:*:*:*
Vendors & Products Topquadrant
Topquadrant topbraid Edg
References

Fri, 27 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
Description TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally.
Title TopQuadrant TopBraid EDG password manager stores external credentials insecurely
First Time appeared Topquadrant
Topquadrant topbraid Edg
CPEs cpe:2.3:a:topquadrant:topbraid_edg:*:*:*:*:*:*:*:*
Vendors & Products Topquadrant
Topquadrant topbraid Edg
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Fri, 27 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
Description TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally.
Weaknesses CWE-257
References

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2025-10-02T14:09:27.993Z

Reserved: 2024-09-05T23:12:56.519Z

Link: CVE-2024-45744

cve-icon Vulnrichment

Updated: 2024-09-27T17:44:29.242Z

cve-icon NVD

Status : Modified

Published: 2024-09-27T16:15:04.940

Modified: 2025-10-02T15:15:52.620

Link: CVE-2024-45744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:44:32Z