CVE-2018-20243: High severity apache fineract vulnerability
Published Oct 13, 2020
·Updated
The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
Affected Software
4 affected components
Apache Fineract>=1.0.0<=1.3.0
Apache Fineract=0.4.0-incubating
Apache Fineract=0.5.0-incubating
Apache Fineract=0.6.0-incubating
Remediation
Event History
Oct 13, 2020
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-20243?
The severity of CVE-2018-20243 is high.
2
What software is affected by CVE-2018-20243?
Apache Fineract versions 1.0.0 to 1.3.0, 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating are affected by CVE-2018-20243.
3
How is the vulnerability CVE-2018-20243 exploited?
The vulnerability CVE-2018-20243 is exploited by implementing POST with the username and password in the URL parameters, which exposes the credentials.
4
Are there any references for CVE-2018-20243?
Yes, you can find references for CVE-2018-20243 at: [link](https://lists.apache.org/thread.html/r040d46835aff3c192656b549ca82f62d87fb044ef9a9dd49408b49b4%40%3Cdev.fineract.apache.org%3E)
5
What is the CWE-ID of CVE-2018-20243?
The CWE-ID of CVE-2018-20243 is 522.