The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2020-10-13T18:23:49

Updated: 2020-10-13T18:23:49

Reserved: 2018-12-19T00:00:00


Link: CVE-2018-20243

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-10-13T19:15:12.367

Modified: 2020-10-16T19:40:16.780


Link: CVE-2018-20243

JSON object: View

cve-icon Redhat Information

No data.

CWE