DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
| Fixed in Apache Fineract 1.3.0 |
|---|
CVE-2016-4977 : Remote code execution
Critical: Known vulnerabilities in spring security dependencies allowed malicious users to trigger remote code execution. Additional details at https://nvd.nist.gov/vuln/detail/CVE-2016-4977
...
Acknowledgements: We would like to thank Roberto Roberto(extranewbugs@gmail.com) for reporting this issue, and the Apache Security team for their assistance.
| Reported to security team | 17 December 2018 |
| Fixed | February 2019 |
| Update Released | 27 March 2019 |
| Issue public | 15 October 2019 |
| Affects | 0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0 |
CVE-2018-11800 and CVE-2018-11801: Apache Fineract SQL Injection Vulnerability
...