DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
This page lists all security vulnerabilities fixed in a released version of Apache Fineract. Each vulnerability is reported via the http://www.apache.org/security/ process and given a security impact rating by the Apache security team - please note that this rating may vary from platform to platform. If you have identified a security issue, email security AT fineract.apache.org.
Amendment of November 29, 2022: In order to ensure that users are given warning of critical issues, the Apache Fineract project may use its relationship with the independent Mifos Initiative to ensure that users of the Fineract backend and Mifos front end UI are informed of such vulnerabilities and are able to assist in testing and validating patches.
| Fixed in Apache Fineract 1.8.1 and 1.7.1 |
|---|
...
Acknowledgements: We would like to thank Sapra co-captain of the Super Guesser CTF team & Security researcher at CRED, for reporting this issue, and the Apache Security team for their assistance. We give kudos and karma to @Aleksandar Vidakovic for resolving this CVE.
| Reported to security team | 31 October 2022 |
| Fixed | 22 November 2022 |
| Update Released | 25 November 2022 |
| Issue public | 29 November 2022 |
| Affects | 0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.7.0, 1.8.0. |
[REFERENCES]:
https://issues.apache.org/jira/projects/FINERACT/issues/FINERACT-1794
...