ZeroHour

CVE-2023-20859

CVSS 3.1
5.5 medium
EPSS
<1%p13
Published
()
Modified
Description

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

Vendors
vmware
Products
spring cloud config, spring cloud vault, spring vault
Weakness
CWE-532
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.