CVE-2022-29405

EUVD-2022-2600
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
apachearchiva
𝑥
< 2.2.8
𝑥
= Vulnerable software versions