cbcvebase.
CVE-2022-29405
published 2022-05-25

CVE-2022-29405: In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8

medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8

Affected

2 ranges
VendorProductVersion rangeFixed in
apachearchiva< 2.2.82.2.8
apache_software_foundationapache_archiva2.2 – 2.2.7