CVE-2024-45744
CVSS V2 None
CVSS V3 None
Description
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally.
Overview
- CVE ID
- CVE-2024-45744
- Assigner
- cisa-cg
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-27T15:56:11.980Z
- Last Modified Date
- 2024-09-27T17:44:33.233Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-45744 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45744 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 15:34:46 | Added to TrackCVE |