Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This page lists all security vulnerabilities fixed in released version of Apache Fineract. Each vulnerability is given a security impact rating by the Apache security team - please note that this rating may vary from platform to platform.

Fixed in Apache Fineract 1.3.0

CVE-2016-4977

Critical:  Known vulnerabilities in spring security dependencies allowed malicious users to trigger remote code execution. Additional details at https://nvd.nist.gov/vuln/detail/CVE-2016-4977

Release branch: The fix is available at https://github.com/apache/fineract/tree/1.3.0

Acknowledgements: We would like to thank Roberto Roberto for reporting this issue, and the Apache Security team for their assistance.

Reported to security team17 December 2018
FixedFebruary 2019
Update Released27 March 2019
Issue public15 October 2019
Affects0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0



CVE-2018-11800 and CVE-2018-11801: Apache Fineract SQL Injection Vulnerability

...

Acknowledgements: We would like to thank Niels Heinen from Google for reporting this issue, and the Apache Security team for reporting this issue for their assistance.

Reported to security team29 August 2018
FixedDecember 2018 & January 2019
Update Released27 March 2019
Issue public9 May 2019
Affects0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0



Fixed in Apache Fineract 1.1.0

...