Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2020-4077 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-24451 Vulnerability in maven package org.jenkins-ci.plugins:cisco-spark-notifier
CVE-2021-21607 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-21613 Vulnerability in maven package io.jenkins.plugins:tics