Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2022-41936 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server
CVE-2021-21691 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-21119 Vulnerability in maven package org.webjars.npm:electron
CVE-2016-7103 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-common