Skip to main content

Insecure Storage of Sensitive Information

CVE-2024-47197

Severity High
Score 7.5/10

Summary

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. Archetype integration testing creates a file called .'/target/classes/archetype-it/archetype-settings.xml'. This file contains all the content from the users '~/.m2/settings.xml' file, which often contains information they do not want to publish. We expect that on many developer machines, this also contains credentials. When the user runs mvn verify again (without a mvn clean), this file becomes part of the final artifact. If a developer were to publish this into Maven Central or any other remote repository (whether as a release or a snapshot) their credentials would be published without them knowing. This issue affects org.apache.maven.plugins:maven-archetype-plugin version 3.2.1.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-922 - Insecure Storage of Sensitive Information

The software stores sensitive information without properly limiting read or write access by unauthorized actors.

Advisory Timeline

  • Published