CVE Vulnerabilities

CVE-2023-20866

Published: Apr 13, 2023 | Modified: Apr 21, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.

Affected Software

Name Vendor Start Version End Version
Spring_session Vmware 3.0.0 (including) 3.0.0 (including)

References