The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2020-10-13T18:23:49

Updated: 2024-08-05T11:58:18.736Z

Reserved: 2018-12-19T00:00:00

Link: CVE-2018-20243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-10-13T19:15:12.367

Modified: 2020-10-16T19:40:16.780

Link: CVE-2018-20243

cve-icon Redhat

No data.