Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Fixed in Apache Fineract 1.3.0

CVE-2016-4977 : Remote code execution

Critical:  Known vulnerabilities in spring security dependencies allowed malicious users to trigger remote code execution. Additional details at https://nvd.nist.gov/vuln/detail/CVE-2016-4977

...

Acknowledgements: We would like to thank Roberto Roberto(extranewbugs@gmail.com) for reporting this issue, and the Apache Security team for their assistance.

Reported to security team17 December 2018
FixedFebruary 2019
Update Released27 March 2019
Issue public15 October 2019
Affects0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0



CVE-2018-11800 and CVE-2018-11801: Apache Fineract SQL Injection Vulnerability

...