CVE-2022-44635: Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44635?
CVE-2022-44635 is a path traversal vulnerability in the file upload component of Apache Fineract, allowing an authenticated user to perform remote code execution.
How does CVE-2022-44635 affect Apache Fineract?
CVE-2022-44635 affects Apache Fineract version 1.8.0 and prior versions.
What is the severity of CVE-2022-44635?
CVE-2022-44635 has a severity rating of 8.8 (high).
How can I fix CVE-2022-44635?
To fix CVE-2022-44635, users are recommended to upgrade Apache Fineract to version 1.8.1 or later.
Where can I find more information about CVE-2022-44635?
More information about CVE-2022-44635 can be found at the following references: [1] [2]