{"id":"CVE-2020-17514","details":"Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful.","modified":"2026-07-08T20:30:39.190512Z","published":"2021-05-27T12:15:07.733Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/rc011b25289c8a6e14f8bc6d07e727382a1df3c8cf2aa5369598bbf64%40%3Cdev.fineract.apache.org%3E"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/05/27/2"},{"type":"FIX","url":"https://issues.apache.org/jira/browse/FINERACT-1211"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/fineract","events":[{"introduced":"0"},{"fixed":"f87b66d4e1beb244bb77b7f084b64e72fd3f697c"}],"database_specific":{"cpe":"cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.5.0"}],"source":"CPE_RANGE"}}],"versions":["1.3.0","1.2.0","1.1.0","1.0.0"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/apache/fineract/commit/f87b66d4e1beb244bb77b7f084b64e72fd3f697c","target":{"file":"fineract-provider/src/main/java/org/apache/fineract/infrastructure/dataqueries/api/RunreportsApiResource.java","function":"runReport"},"deprecated":false,"digest":{"function_hash":"106474929361225198308851064867287969644","length":893},"id":"CVE-2020-17514-22ad9a96","signature_type":"Function"},{"digest":{"line_hashes":["280530891970670539376843024154011340833","49914397998138737485537880196239095205","208630785006039122057017105586735474035","15961524931943988623102602731569372254"],"threshold":0.9},"id":"CVE-2020-17514-5e6fcf1a","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/fineract/commit/f87b66d4e1beb244bb77b7f084b64e72fd3f697c","target":{"file":"fineract-provider/src/main/java/org/apache/fineract/infrastructure/dataqueries/service/ReadReportingService.java"},"deprecated":false},{"target":{"file":"fineract-provider/src/main/java/org/apache/fineract/infrastructure/reportmailingjob/service/ReportMailingJobWritePlatformServiceImpl.java"},"deprecated":false,"digest":{"line_hashes":["235044639398674271974919262124490233004","220862674770124498097607656203942822792","340071168976289991808803488580652321004","293758616914316666127019760345790182609"],"threshold":0.9},"id":"CVE-2020-17514-7e3c22a1","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/fineract/commit/f87b66d4e1beb244bb77b7f084b64e72fd3f697c"},{"deprecated":false,"digest":{"function_hash":"150538795255760092079093291453021380984","length":1521},"id":"CVE-2020-17514-946be5b1","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/fineract/commit/f87b66d4e1beb244bb77b7f084b64e72fd3f697c","target":{"file":"fineract-provider/src/main/java/org/apache/fineract/infrastructure/reportmailingjob/service/ReportMailingJobWritePlatformServiceImpl.java","function":"generateReportOutputStream"}},{"digest":{"function_hash":"258071128671093110070062218547965101331","length":448},"id":"CVE-2020-17514-c41b6889","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/fineract/commit/f87b66d4e1beb244bb77b7f084b64e72fd3f697c","target":{"function":"getReportType","file":"fineract-provider/src/main/java/org/apache/fineract/infrastructure/dataqueries/service/ReadReportingServiceImpl.java"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/fineract/commit/f87b66d4e1beb244bb77b7f084b64e72fd3f697c","target":{"file":"fineract-provider/src/main/java/org/apache/fineract/infrastructure/dataqueries/api/RunreportsApiResource.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["133901955411038297603702634634361417280","51969418121777140423287985491175926186","301273296032243751978956290713798537899","335937948156775573000532487112851869802"]},"id":"CVE-2020-17514-c8e6761e"},{"target":{"file":"fineract-provider/src/main/java/org/apache/fineract/infrastructure/dataqueries/service/ReadReportingServiceImpl.java"},"deprecated":false,"digest":{"line_hashes":["15071055183209831028850922596960473857","305469393546537005401088465954151196261","311640587452877026191815268600126891539","161014423631986323815603068570084703882"],"threshold":0.9},"id":"CVE-2020-17514-cc7202e2","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/fineract/commit/f87b66d4e1beb244bb77b7f084b64e72fd3f697c"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-17514.json","vanir_signatures_modified":"2026-07-08T20:30:39Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}