PT-2022-19580 · Apache · Apache Archiva

Published

2022-05-25

·

Updated

2023-08-08

·

CVE-2022-29405

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Archiva versions prior to 2.2.8
Description The issue allows any registered user to reset the password for any other user.
Recommendations For versions prior to 2.2.8, update to version 2.2.8 to resolve the issue.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-29405
GHSA-5HQC-X78W-3CMW

Affected Products

Apache Archiva