Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2022-23618 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-46682 Vulnerability in maven package org.jenkins-ci.plugins:plot
CVE-2022-34802 Vulnerability in maven package org.jenkins-ci.plugins:rocketchatnotifier
CVE-2023-37947 Vulnerability in maven package org.openshift.jenkins:openshift-login
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka_2.13