CVE-2025-58130: Apache Fineract: Server Key not masked
Published Dec 11, 2025
·Updated
Insufficiently Protected Credentials vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1.
Users are encouraged to upgrade to version 1.13.0, the latest release.
Affected Software
2 affected components
Apache Fineract<=1.11.0
Apache Fineract<1.12.1
Event History
Dec 12, 2025
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58130?
CVE-2025-58130 is classified as a vulnerability affecting Apache Fineract due to insufficiently protected credentials.
2
How do I fix CVE-2025-58130?
To fix CVE-2025-58130, users should upgrade to version 1.12.1 or later of Apache Fineract.
3
Which versions of Apache Fineract are affected by CVE-2025-58130?
CVE-2025-58130 affects Apache Fineract versions up to and including 1.11.0.
4
What steps should I take if I'm using a vulnerable version of Apache Fineract?
If using a vulnerable version of Apache Fineract, you should immediately upgrade to version 1.12.1 or later to mitigate the risk.
5
Is there a patch available for CVE-2025-58130?
Yes, a patch for CVE-2025-58130 is included in version 1.12.1 and later releases of Apache Fineract.