This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0.
Users are encouraged to upgrade to version 1.13.0, the latest release.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 18 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache fineract |
|
| Vendors & Products |
Apache
Apache fineract |
Fri, 12 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 12 Dec 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to upgrade to version 1.13.0, the latest release. | |
| Title | Apache Fineract: weak password policy | |
| Weaknesses | CWE-521 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-12-18T15:34:00.875Z
Reserved: 2025-01-15T23:55:29.758Z
Link: CVE-2025-23408
Updated: 2025-12-12T10:06:07.346Z
Status : Analyzed
Published: 2025-12-12T10:15:48.870
Modified: 2025-12-18T14:54:10.013
Link: CVE-2025-23408
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:16:30Z