Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This page lists all security vulnerabilities fixed in a released version of Apache Fineract. Each vulnerability is reported via the http://www.apache.org/security/ process and given a security impact rating by the Apache security team - please note that this rating may vary from platform to platform.  If you have identified a security issue, email security AT fineract.apache.org.  

Amendment of November 29, 2022:  In order to ensure that users are given warning of critical issues, the Apache Fineract project may use its relationship with the independent Mifos Initiative to ensure that users of the Fineract backend and Mifos front end UI are informed of such vulnerabilities and are able to assist in testing and validating patches.  


Fixed in Apache Fineract 1.8.1 and 1.7.1

...

Acknowledgements: We would like to thank  Sapra co-captain of the Super Guesser CTF team & Security researcher at CRED, for reporting this issue, and the Apache Security team for their assistance.  We give kudos and karma to @Aleksandar Vidakovic for resolving this CVE. 

Reported to security team31 October 2022
Fixed22 November 2022 
Update Released25 November 2022
Issue public29 November 2022
Affects0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.7.0, 1.8.0. 


[REFERENCES]:  
https://issues.apache.org/jira/projects/FINERACT/issues/FINERACT-1794   

...