Description
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2600 | In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 |
Github GHSA |
GHSA-5hqc-x78w-3cmw | Missing Authorization in Apache Archiva |
References
| Link | Providers |
|---|---|
| https://archiva.apache.org/docs/2.2.8/release-notes.html |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T06:17:55.082Z
Reserved: 2022-04-18T00:00:00.000Z
Link: CVE-2022-29405
No data.
Status : Modified
Published: 2022-05-25T08:15:12.167
Modified: 2024-11-21T06:59:01.143
Link: CVE-2022-29405
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA