CVE-2020-17514

Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-05-27 12:15

Updated : 2023-11-07 03:19


NVD link : CVE-2020-17514

Mitre link : CVE-2020-17514

CVE.ORG link : CVE-2020-17514


JSON object : View

Products Affected

apache

  • fineract