CVE-2024-45744

CVSS 3.1 Score 3 of 10 (low)

Details

Published Sep 27, 2024
Updated: Feb 18, 2025
CWE ID 257

Summary

CVE-2024-45744: TopQuadrant's TopBraid EDG software stores external credentials in an insecure manner, allowing authenticated attackers with file system access to obtain the secret key from edg-setup.properties and decrypt passwords in edg-vault.properties. This vulnerability can be exploited in combination with other vulnerabilities, such as CVE-2024-45745, to gain file system access. Affected versions include at least 7.1.3, while version 7.3 integrates with HashiCorp Vault to store passwords more securely, and version 8.3.0 issues a warning when using plain text secrets.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share