First published: Wed May 25 2022(Updated: )
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Archiva | <2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29405 is classified as a high severity vulnerability due to its potential for unauthorized password resets.
To fix CVE-2022-29405, upgrade Apache Archiva to version 2.2.8 or later.
CVE-2022-29405 allows any registered user to reset the passwords of other users, compromising account security.
CVE-2022-29405 affects all versions of Apache Archiva prior to 2.2.8.
There is no known workaround for CVE-2022-29405; upgrading is recommended for security.