Apache Fineract: SSRF template type vulnerability in certain authenticated users
CVE-2023-25195

8.1HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
28 March 2023

Summary

An SSRF vulnerability has been identified in Apache Fineract, which allows authorized users with limited permissions to exploit the server. This compromise can enable the malicious user to access internal resources and potentially leverage the server for unauthorized outbound communication. Affected versions range from 1.4 to 1.8.3, making it essential for users to review their security measures and apply patches as needed.

Affected Version(s)

Apache Fineract 1.4 <= 1.8.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Huydoppa from GHTK
Aleksander
.