The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2020-10-13T18:23:49

Updated: 2024-08-05T11:58:18.736Z

Reserved: 2018-12-19T00:00:00

Link: CVE-2018-20243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-13T19:15:12.367

Modified: 2024-11-21T04:01:09.367

Link: CVE-2018-20243

cve-icon Redhat

No data.