Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2016-5016 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2016-3088 Vulnerability in maven package org.apache.activemq:apache-activemq
CVE-2022-24822 Vulnerability in npm package @podium/layout
CVE-2019-10339 Vulnerability in maven package org.jenkins-ci.plugins:jx-resources
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity