cbcvebase.
CVE-2023-20859
published 2023-03-23

CVE-2023-20859: In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

Affected

6 ranges
VendorProductVersion rangeFixed in
vmwarespring_cloud_config3.1.0 – 3.1.6
vmwarespring_cloud_config4.0.0 – 4.0.1
vmwarespring_cloud_vault
vmwarespring_cloud_vault3.1.0 – 3.1.2
vmwarespring_vault>= 2.3.0 < 2.3.32.3.3
vmwarespring_vault>= 3.0.0 < 3.0.23.0.2