Vulnerability Details CVE-2022-29405
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 72.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2022-29405
-
cpe:2.3:a:apache:archiva:0.9
-
cpe:2.3:a:apache:archiva:1.0
-
cpe:2.3:a:apache:archiva:1.0.1
-
cpe:2.3:a:apache:archiva:1.0.2
-
cpe:2.3:a:apache:archiva:1.1
-
cpe:2.3:a:apache:archiva:1.1.1
-
cpe:2.3:a:apache:archiva:1.1.2
-
cpe:2.3:a:apache:archiva:1.1.3
-
cpe:2.3:a:apache:archiva:1.1.4
-
cpe:2.3:a:apache:archiva:1.2
-
cpe:2.3:a:apache:archiva:1.2.1
-
cpe:2.3:a:apache:archiva:1.2.2
-
cpe:2.3:a:apache:archiva:1.3
-
cpe:2.3:a:apache:archiva:1.3.1
-
cpe:2.3:a:apache:archiva:1.3.2
-
cpe:2.3:a:apache:archiva:1.3.3
-
cpe:2.3:a:apache:archiva:1.3.4
-
cpe:2.3:a:apache:archiva:1.3.5
-
cpe:2.3:a:apache:archiva:1.3.6
-
cpe:2.3:a:apache:archiva:1.3.8
-
cpe:2.3:a:apache:archiva:1.3.9
-
cpe:2.3:a:apache:archiva:1.4
-
cpe:2.3:a:apache:archiva:2.0.0
-
cpe:2.3:a:apache:archiva:2.0.1
-
cpe:2.3:a:apache:archiva:2.1.0
-
cpe:2.3:a:apache:archiva:2.1.1
-
cpe:2.3:a:apache:archiva:2.2.0
-
cpe:2.3:a:apache:archiva:2.2.1
-
cpe:2.3:a:apache:archiva:2.2.2
-
cpe:2.3:a:apache:archiva:2.2.3
-
cpe:2.3:a:apache:archiva:2.2.4
-
cpe:2.3:a:apache:archiva:2.2.5
-
cpe:2.3:a:apache:archiva:2.2.6
-
cpe:2.3:a:apache:archiva:2.2.7