Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.
History

Fri, 25 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2022-11-29T00:00:00.000Z

Updated: 2025-04-25T14:51:14.718Z

Reserved: 2022-11-02T00:00:00.000Z

Link: CVE-2022-44635

cve-icon Vulnrichment

Updated: 2024-08-03T13:54:03.993Z

cve-icon NVD

Status : Modified

Published: 2022-11-29T15:15:10.897

Modified: 2025-04-25T15:15:33.310

Link: CVE-2022-44635

cve-icon Redhat

No data.