Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Remediation
References
https://archiva.apache.org/docs/2.2.8/release-notes.html
Related Vulnerabilities
CVE-2018-1229 Vulnerability in maven package org.springframework.batch:spring-batch-admin
CVE-2017-12623 Vulnerability in maven package org.apache.nifi:nifi-security-utils
CVE-2022-37734 Vulnerability in maven package com.graphql-java:graphql-java
CVE-2023-27094 Vulnerability in maven package cn.hippo4j:hippo4j-all
CVE-2023-28680 Vulnerability in maven package org.jenkins-ci.plugins:crap4j