CVE Vulnerabilities

CVE-2023-20859

Insertion of Sensitive Information into Log File

Published: Mar 23, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Spring_cloud_configVmware3.1.0 (including)3.1.6 (including)
Spring_cloud_configVmware4.0.0 (including)4.0.1 (including)
Spring_cloud_vaultVmware3.1.0 (including)3.1.2 (including)
Spring_cloud_vaultVmware4.0.0 (including)4.0.0 (including)
Spring_vaultVmware2.3.0 (including)2.3.3 (excluding)
Spring_vaultVmware3.0.0 (including)3.0.2 (excluding)

Potential Mitigations

References