Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This page lists all security vulnerabilities fixed in a released version of Apache Fineract. Each vulnerability is reported via the http://www.apache.org/security/ process and given a security impact rating by the Apache security team - please note that this rating may vary from platform to platform.  If you have identified a security issue, email security AT fineract.apache.org.  


Fixed in Apache Fineract 1.5.0


CVE-2020-17514: Disabled Hostname verification for HTTPS  

...

Acknowledgements: We would like to thank Simon Gerst at https://github.com/intrigus-lgtm for reporting this issue, and the Apache Security team for their assistance. 

Reported to security team
12
15 October 2020 
Fixed19 October 2020
Update Released23 May  2021
Issue public26 May 2021
Affects0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0

[REFERENCES]:  

https://issues.apache.org/jira/browse/FINERACT-1211 

...