Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Fixed in Apache Fineract 1.8.4 and 1.7.3


CVE-2023-25195

DESCRIPTION: 

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract.

Authorized users with limited permissions can gain access to server and may be able to use server for any outbound traffic. 

This issue affects Apache Fineract: from 1.4 through 1.8.3.


Release branch: The fix is available at  1.8.4  and 1.7.3 patches.  

1.8.4 - Apache Fineract

1.7.3 - Apache Fineract 

Acknowledgements: We would like to thank Huydoppa from GHTK, for reporting this issue, and the Apache Security team for their assistance.  Thank you to Aleks@apache.org for resolving this CVE

Reported to security team06-Dec-2022
Fixed01-March-2023
Update Released24-March-2023
Issue public27-March-2023
Affects1.8.3 and earlier releases


[REFERENCES]:  

Jira
serverASF JIRA
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyFINERACT-1872



CVE-2023-25196

DESCRIPTION: 

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract.

This issue affects Apache Fineract: from 1.4 through 1.8.2.


Release branch: The fix is available at  1.8.4  and 1.7.3 patches.  

1.8.4 - Apache Fineract

1.7.3 - Apache Fineract 

Acknowledgements: We would like to thank Zhang Baocheng at Leng Jing Qi Cai Security Lab, for reporting this issue, and the Apache Security team for their assistance.  Thank you to aleks@apache.org for resolving this CVE. 

Reported to security team02-December-2022
Fixed01-March-2023
Update Released24-March-2023
Issue public27-March-2023
Affects1.8.3 and earlier releases


[REFERENCES]:  

Jira
serverASF JIRA
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyFINERACT-1868



CVE-2023-25197

DESCRIPTION: 

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract.

This issue affects apache fineract: from 1.4 through 1.8.2.


Release branch: The fix is available at  1.8.4  and 1.7.3 patches.  

1.8.4 - Apache Fineract

1.7.3 - Apache Fineract 

Acknowledgements: We would like to thank Eugene Lim at Cyber Security Group (CSG) Government Technology Agency GOVTECH.sg, for reporting this issue, and the Apache Security team for their assistance.  Thank you to @Aleksandar Vidakovic for resolving this CVE. 

Reported to security team
Fixed
Update Released
Issue public
Affects1.8.3 and earlier releases


[REFERENCES]:  

Jira
serverASF JIRA
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyFINERACT-1870


---------------------------------------------------------------------------------------------

Fixed in Apache Fineract 1.8.1 and 1.7.1

CVE-2022-44635: file upload vulnerability 

...

[REFERENCES]:  
https://issues.apache.org/jira/projects/FINERACT/issues/FINERACT-1794   



---------------------------------------------------------------------------------------------

Fixed in Apache Fineract 1.5.0

...