Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The Apache Fineract project recommends that you secure the platform by not running it directly on the internet.  IP filtering and other techniques may be essential for all API ingress.  In particular, simply running the solution in default mode, connecting it with a front end UI, is not considered best practice for a production environment of fineract unless additional security layers and practices are added.  

Fixed in Apache Fineract 1.9.0

On 27 February 2024 we announced End of Life of Version 1.8.*.   All previous versions may be vulnerable to the following CVEs and we urge our users to upgrade to the latest. 

...

Description:  Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role, including super user status. This flaw could enable users to gain control over user management.

Fixed by https://github.com/apache/fineract/pull/3626


Reported to security team4 Sept 2023
Fixed6 Dec 2023
Update Released12 Jan 2024
Issue public15 March 2024
Affects1.8.4 and earlier releases

Acknowledgements:  We thank Yash Sancheti of gh GH Solutions Consultants for reporting this issue. 

...

Description:  Under certain system configurations, the sqlSearch parameter was vulnerable to blind SQL injection attacks, potentially allowing attackers to manipulate database queries.

Fixed by https://github.com/apache/fineract/pull/3626


Reported to security team9 Aug 2023
Fixed6 Dec 2023
Update Released12 Jan 2024
Issue public15 March 2024
Affects1.8.4 and earlier releases

Acknowledgements:  We thank Majd Alasfar of ProgressSoft for reporting this issue. 

...

Description:  Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.

Fixed by https://github.com/apache/fineract/pull/3621


Reported to security team4 Sept 2023
Fixed6 Dec 2023
Update Released12 Jan 2024
Issue public15 March 2024
Affects1.8.4 and earlier releases

Acknowledgements:  We thank Yash Sancheti of gh GH Solutions Consultants for reporting this issue. 

...