Finastra maintains a focused portfolio of web application and server-side rendering products, including its NestJS-based proxy and SSR components, serving financial services infrastructure. The observed vulnerability footprint centers on application-layer input-handling and information-disclosure issues, including path traversal, cross-site scripting, and sensitive data exposure—weaknesses typical of complex web frameworks operating in sensitive operational contexts. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Finastra over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31069HIGH NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to control when Authorization headers should should | Jun 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-24718MEDIUM ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the | Mar 1, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-24717MEDIUM ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.5, a cross site scripting (XSS) issue can occur when providing untrusted | Mar 1, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-31070HIGH NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to block sensitive cookies (e.g. session cookies) f | Jun 15, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Finastra.
Media articles that mention a CVE ID that affects a product developed by Finastra — matched by CVE ID, not by vendor name.