Security Advisory

CVE-2022-44635

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-11-29 00:00:00
Last updated 2025-04-25 14:51:14
Assigner apache
State PUBLISHED

Description

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.