Maven Archetype 插件:Maven Archetype 集成测试可能会将本地设置打包到已发布的工件中,可能包含凭据(CVE-2024-47197)

admin 2024-09-29 01:39:45 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
Maven Archetype 插件:Maven Archetype 集成测试可能会将本地设置打包到已发布的工件中,可能包含凭据(CVE-2024-47197)

CVE编号

CVE-2024-47197

利用情况

暂无

补丁情况

N/A

披露时间

2024-09-26
漏洞描述
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to upgrade to version 3.3.0, which fixes the issue. Archetype integration testing creates a file called ./target/classes/archetype-it/archetype-settings.xml This file contains all the content from the users ~/.m2/settings.xml file, which often contains information they do not want to publish. We expect that on many developer machines, this also contains credentials. When the user runs mvn verify again (without a mvn clean), this file becomes part of the final artifact. If a developer were to publish this into Maven Central or any other remote repository (whether as a release or a snapshot) their credentials would be published without them knowing.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://lists.apache.org/thread/ftg81np183wnyk0kg4ks95dvgxdrof96
CVSS3评分 N/A
  • 攻击路径 N/A
  • 攻击复杂度 N/A
  • 权限要求 N/A
  • 影响范围 N/A
  • 用户交互 N/A
  • 可用性 N/A
  • 保密性 N/A
  • 完整性 N/A
N/A
CWE-ID 漏洞类型
CWE-200 信息暴露
CWE-922 敏感信息的不安全存储
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-47044利用情况 暂无补丁情况 N/A披露时间 2024-09-26漏洞描述NIPPON TELEGRAPH AND
评论:0   参与:  0