CVE-2025-23408: Apache Fineract: weak password policy
Published Dec 11, 2025
·Updated
Weak Password Requirements vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0.
Users are encouraged to upgrade to version 1.13.0, the latest release.
Affected Software
3 affected components
Apache Fineract<=1.10.1
Apache Fineract>1.11.0
Apache Fineract<1.11.0
Event History
Dec 12, 2025
CVE Published
via MITRE·09:18 AM
Data Sourced
via MITRE·09:18 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23408?
The CVE-2025-23408 vulnerability is classified as a weak password requirement issue affecting Apache Fineract.
2
How do I fix CVE-2025-23408?
To remediate CVE-2025-23408, upgrade Apache Fineract to version 1.11.0 or later.
3
Which versions of Apache Fineract are affected by CVE-2025-23408?
CVE-2025-23408 affects Apache Fineract versions prior to 1.11.0.
4
What should users do if they are using version 1.10.1 of Apache Fineract concerning CVE-2025-23408?
Users on version 1.10.1 should upgrade to at least version 1.11.0 to address CVE-2025-23408.
5
Is there a recommended version to upgrade to in relation to CVE-2025-23408?
It is recommended to upgrade to version 1.13.0 of Apache Fineract for the best security practices against CVE-2025-23408.