Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-r47r-87p9-8jh3: Spring Vault vulnerable to insertion of sensitive information into a log file

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

ghsa
#git

Spring Vault vulnerable to insertion of sensitive information into a log file

Moderate severity GitHub Reviewed Published Mar 23, 2023 to the GitHub Advisory Database • Updated Mar 23, 2023

Related news

CVE-2023-20859: CVE-2023-20859: Insertion of Sensitive Information into Log Sourced from Failed Revocation of Tokens

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.