Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Fixed in Apache Fineract 1.8.1 and 1.7.1

CVE-2022-44635: file upload vulnerability 

[DESCRIPTION]:  Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code.  This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.


Under certain conditions of the runtime, a malicious actor could execute code remotely 

Critical:  Apache Fineract fails to protect against a vector of attack.  

Under typical deployments, remote code could be run.  

Release branch: The fix is available at  1.8.1  and 1.7.1 patches.  

1.8.1 - Apache Fineract

1.7.1 - Apache Fineract 

Acknowledgements: We would like to thank  Sapra co-captain of the Super Guesser CTF team & Security researcher at CRED, for reporting this issue, and the Apache Security team for their assistance.  We give kudos and karma to @Aleksandar Vidakovic for resolving this CVE. 

Reported to security team31 October 2022
Fixed22 November 2022 
Update Released25 November 2022
Issue public29 November 2022
Affects0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.7.0, 1.8.0. 


[REFERENCES]:  
https://issues.apache.org/jira/projects/FINERACT/issues/FINERACT-1794   




Fixed in Apache Fineract 1.5.0


CVE-2020-17514: Disabled Hostname verification for HTTPS  

...