https://seclists.org/oss-sec/2024/q1/265: CVE-2024-23537: Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role.
Published Mar 29, 2024
·Updated
Affected Software
1 affected component
Apache Fineract
Frequently Asked Questions
1
What is the severity of CVE-2024-23537?
The severity of CVE-2024-23537 is rated as high due to its potential for privilege escalation.
2
How do I fix CVE-2024-23537?
To fix CVE-2024-23537, update Apache Fineract to the latest version that addresses this vulnerability.
3
What versions of Apache Fineract are affected by CVE-2024-23537?
CVE-2024-23537 affects certain versions of Apache Fineract; always refer to the latest release notes for specific version details.
4
Who is impacted by CVE-2024-23537?
Users of Apache Fineract can be impacted by CVE-2024-23537 if they have roles that could be escalated without proper permissions.
5
What causes CVE-2024-23537 in Apache Fineract?
CVE-2024-23537 is caused by a flaw in the permission validation mechanism within Apache Fineract.