DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
| Fixed in Apache Fineract 1.8.1 and 1.7.1 |
|---|
CVE-2022-44635: file upload vulnerability
[DESCRIPTION]: Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.
Under certain conditions of the runtime, a malicious actor could execute code remotely
Critical: Apache Fineract fails to protect against a vector of attack.
Under typical deployments, remote code could be run.
Release branch: The fix is available at 1.8.1 and 1.7.1 patches.
Acknowledgements: We would like to thank Sapra co-captain of the Super Guesser CTF team & Security researcher at CRED, for reporting this issue, and the Apache Security team for their assistance. We give kudos and karma to @Aleksandar Vidakovic for resolving this CVE.
| Reported to security team | 31 October 2022 |
| Fixed | 22 November 2022 |
| Update Released | 25 November 2022 |
| Issue public | 29 November 2022 |
| Affects | 0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.7.0, 1.8.0. |
[REFERENCES]:
https://issues.apache.org/jira/projects/FINERACT/issues/FINERACT-1794
| Fixed in Apache Fineract 1.5.0 |
|---|
CVE-2020-17514: Disabled Hostname verification for HTTPS
...