TopQuadrant TopBraid EDG password manager stores external credentials insecurely
Vulnerability Description
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45744
Credits & Attribution
No credits recorded in the NVD database.
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json
- https://www.topquadrant.com/doc/latest/reference/PasswordManagementAdminPage.html
- https://www.topquadrant.com/doc/latest/administrator_guide/edg_installation_and_authentication/hashicorp_integration.html
- https://www.topquadrant.com/release-note/7-3/
- https://www.topquadrant.com/wp-content/uploads/2025/02/changes-8.3.0.txt
More from TopQuadrant
View All →Affected Vendor
TopQuadrant
View all reports →