Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2023-43496 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-37478 Vulnerability in npm package @pnpm/linuxstatic-arm64
CVE-2020-2247 Vulnerability in maven package org.jenkins-ci.plugins:klocwork
CVE-2017-7678 Vulnerability in maven package org.apache.spark:spark-core_2.10
CVE-2021-21619 Vulnerability in maven package org.jenkins-ci.plugins:claim