CVE-2018-20243

Source
https://cve.org/CVERecord?id=CVE-2018-20243
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20243.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-20243
Published
2020-10-13T19:15:12.367Z
Modified
2026-03-14T09:28:58.431931Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.

References

Affected packages

Git / github.com/apache/fineract

Affected ranges

Type
GIT
Repo
https://github.com/apache/fineract
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.3.0"
        }
    ]
}

Affected versions

1.*
1.0.0
1.1.0
1.2.0
1.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20243.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "0.4.0-incubating"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "0.5.0-incubating"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "0.6.0-incubating"
            }
        ]
    }
]