Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2016-5016 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2018-20677 Vulnerability in npm package bootstrap
CVE-2023-46131 Vulnerability in maven package org.grails:grails-encoder
CVE-2010-2232 Vulnerability in maven package org.apache.derby:derby
CVE-2023-25157 Vulnerability in maven package org.geoserver.community:gs-jdbcconfig