Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8xf3-x93c-2ch6

Опубликовано: 27 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3

Описание

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally.

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally.

EPSS

Процентиль: 9%
0.00033
Низкий

3 Low

CVSS3

Дефекты

CWE-257
CWE-522

Связанные уязвимости

CVSS3: 3
nvd
больше 1 года назад

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.

EPSS

Процентиль: 9%
0.00033
Низкий

3 Low

CVSS3

Дефекты

CWE-257
CWE-522