Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-47197

23
FAUCET Score

CVE-2024-47197 is a sensitive information exposure vulnerability in the Maven Archetype Plugin, affecting versions from 3.2.1 before 3.3.0. During integration testing, the plugin inadvertently copies the user's ~/.m2/settings.xml file, which often contains credentials, into the final artifact if mvn clean is not run. This could lead to the publication of sensitive credentials if the artifact is uploaded to a remote repository. Rated 7.5 HIGH on CVSS, this vulnerability has a network attack vector and high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
3.2.1CPE matchmatch criteria
cpe:2.3:a:apache:maven_archetype:3.2.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.84%
Probability of exploitation in next 30 days
EPSS Percentile
54.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0084 is in the 29th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

mavenpatch availablevia ghsa
Product: org.apache.maven.plugins:maven-archetype-pluginFixed in: 3.3.0
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: A-MQ Clients 2Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 3Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 4Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat Build of KeycloakFixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat build of QuarkusFixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Data Grid 7Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.apache.maven.plugins/maven-archetype-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat Process Automation 7Fixed in: org.apache.maven.plugins/maven-archetype-plugin

Vendor Advisories (2)

mavenGHSA-2qq7-fch2-phqflow

Maven Archetype Plugin: Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentials

Sep 26, 2024
redhatCVE-2024-47197Low

maven-archetype-plugin: Exposure of Sensitive Information

Sep 26, 2024

References

openwall.com / lists/oss-security/2024/09/26/2
lists.apache.org / thread/ftg81np183wnyk0kg4ks95dvgxdrof96
Mailing List