Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2022-29214 Vulnerability in npm package next-auth
CVE-2018-1000149 Vulnerability in maven package org.jenkins-ci.plugins:ansible
CVE-2022-41247 Vulnerability in maven package org.jenkins-ci.plugins:bigpanda-jenkins
CVE-2022-23221 Vulnerability in maven package com.h2database:h2
CVE-2021-21618 Vulnerability in maven package org.jenkins-ci.plugins:repository-connector