Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-jdk15to18
CVE-2023-28672 Vulnerability in maven package org.jenkinsci.plugins:octoperf
CVE-2020-2129 Vulnerability in maven package org.apache.maven.plugins:maven-compiler-plugin
CVE-2022-24785 Vulnerability in npm package moment
CVE-2019-10449 Vulnerability in maven package org.jenkins-ci.plugins:fortify-on-demand-uploader