Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2023-41339 Vulnerability in maven package org.geoserver:gs-wms
CVE-2023-24456 Vulnerability in maven package org.jenkins-ci.plugins:keycloak
CVE-2018-19048 Vulnerability in npm package simditor
CVE-2023-44794 Vulnerability in maven package cn.dev33:sa-token-core