CVE Published: 23/03/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: vmware |
Vendor: n/a |
Product: Spring Vault, Spring Cloud Vault, Spring Cloud Config Status : PUBLISHED
CVE-2023-20859 Description
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.