<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">maven-archetype-3.3.0-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:14372-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-09-27T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-09-27T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-09-27T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">maven-archetype-3.3.0-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the maven-archetype-3.3.0-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-14372</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/F5AIDOTX2VOI34RL4X3LUJRIOBWTRLGU/</URL>
      <Description>E-Mail link for openSUSE-SU-2024:14372-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-47197/</URL>
      <Description>SUSE CVE CVE-2024-47197 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="maven-archetype-3.3.0-1.1">
      <FullProductName ProductID="maven-archetype-3.3.0-1.1">maven-archetype-3.3.0-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="maven-archetype-catalog-3.3.0-1.1">
      <FullProductName ProductID="maven-archetype-catalog-3.3.0-1.1">maven-archetype-catalog-3.3.0-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="maven-archetype-common-3.3.0-1.1">
      <FullProductName ProductID="maven-archetype-common-3.3.0-1.1">maven-archetype-common-3.3.0-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="maven-archetype-descriptor-3.3.0-1.1">
      <FullProductName ProductID="maven-archetype-descriptor-3.3.0-1.1">maven-archetype-descriptor-3.3.0-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="maven-archetype-javadoc-3.3.0-1.1">
      <FullProductName ProductID="maven-archetype-javadoc-3.3.0-1.1">maven-archetype-javadoc-3.3.0-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="maven-archetype-packaging-3.3.0-1.1">
      <FullProductName ProductID="maven-archetype-packaging-3.3.0-1.1">maven-archetype-packaging-3.3.0-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="maven-archetype-plugin-3.3.0-1.1">
      <FullProductName ProductID="maven-archetype-plugin-3.3.0-1.1">maven-archetype-plugin-3.3.0-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="maven-archetype-3.3.0-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:maven-archetype-3.3.0-1.1">maven-archetype-3.3.0-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="maven-archetype-catalog-3.3.0-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:maven-archetype-catalog-3.3.0-1.1">maven-archetype-catalog-3.3.0-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="maven-archetype-common-3.3.0-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:maven-archetype-common-3.3.0-1.1">maven-archetype-common-3.3.0-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="maven-archetype-descriptor-3.3.0-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:maven-archetype-descriptor-3.3.0-1.1">maven-archetype-descriptor-3.3.0-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="maven-archetype-javadoc-3.3.0-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:maven-archetype-javadoc-3.3.0-1.1">maven-archetype-javadoc-3.3.0-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="maven-archetype-packaging-3.3.0-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:maven-archetype-packaging-3.3.0-1.1">maven-archetype-packaging-3.3.0-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="maven-archetype-plugin-3.3.0-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:maven-archetype-plugin-3.3.0-1.1">maven-archetype-plugin-3.3.0-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin.

This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0.

Users are recommended to upgrade to version 3.3.0, which fixes the issue.

Archetype integration testing creates a file
called ./target/classes/archetype-it/archetype-settings.xml
This file contains all the content from the users ~/.m2/settings.xml file,
which often contains information they do not want to publish. We expect that on many developer machines, this also contains
credentials.

When the user runs mvn verify again (without a mvn clean), this file becomes part of
the final artifact.

If a developer were to publish this into Maven Central or any other remote repository (whether as a release
or a snapshot) their credentials would be published without them knowing.</Note>
    </Notes>
    <CVE>CVE-2024-47197</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:maven-archetype-3.3.0-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:maven-archetype-catalog-3.3.0-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:maven-archetype-common-3.3.0-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:maven-archetype-descriptor-3.3.0-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:maven-archetype-javadoc-3.3.0-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:maven-archetype-packaging-3.3.0-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:maven-archetype-plugin-3.3.0-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/F5AIDOTX2VOI34RL4X3LUJRIOBWTRLGU/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-47197.html</URL>
        <Description>CVE-2024-47197</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231000</URL>
        <Description>SUSE Bug 1231000</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
