CVE-2023-20859
23.03.2023, 21:15
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | spring_cloud_config | 3.1.0 ≤ 𝑥 ≤ 3.1.6 |
vmware | spring_cloud_config | 4.0.0 ≤ 𝑥 ≤ 4.0.1 |
vmware | spring_cloud_vault | 3.1.0 ≤ 𝑥 ≤ 3.1.2 |
vmware | spring_cloud_vault | 4.0.0 |
vmware | spring_vault | 2.3.0 ≤ 𝑥 < 2.3.3 |
vmware | spring_vault | 3.0.0 ≤ 𝑥 < 3.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration