CVE-2023-25195: Apache Fineract

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain access to server and may be able to use server for any outbound traffic.  This issue affects Apache Fineract: from 1.4 through 1.8.3.

Affected products

  • Apache Fineract: from 1.4.0, up to and including 1.8.3

Published 2023-03-28. Last modified 2026-06-17.