CVE-2018-20243Insufficiently Protected Credentials in Apache Fineract

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 24

Description

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/fineract1.0.01.3.0+3
CVEListV5apache_software_foundation/apache_fineract0.4.0-incubating, 0.5.0-incubating, 0.6.0-incubating, 1.0.0, 1.1.0, 1.2.0, 1.3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5f27-8j8c-cr98: The implementation of POST with the username and password in the URL parameters exposed the credentials2022-05-24
CVEList
CVE-2018-20243: The implementation of POST with the username and password in the URL parameters exposed the credentials2020-10-13
CVE-2018-20243 — Insufficiently Protected Credentials | cvebase