CVE-2023-20859
Published Mar 23, 2023
Last updated 2 years ago
Overview
- Description
- In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
- Source
- security@vmware.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
Weaknesses
- nvd@nist.gov
- CWE-532
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27E7C265-DE73-4FE5-BAE9-D6FD0B838B90", "versionEndIncluding": "3.1.6", "versionStartIncluding": "3.1.0" }, { "criteria": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A42F633-1074-46A8-AB65-DF694B34F650", "versionEndIncluding": "4.0.1", "versionStartIncluding": "4.0.0" }, { "criteria": "cpe:2.3:a:vmware:spring_cloud_vault:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B545C7F6-40FB-4010-9146-1ED3FB861E79", "versionEndIncluding": "3.1.2", "versionStartIncluding": "3.1.0" }, { "criteria": "cpe:2.3:a:vmware:spring_cloud_vault:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDBE7574-C6A7-4EE3-B7BE-5D867E1034BF" }, { "criteria": "cpe:2.3:a:vmware:spring_vault:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2216E96-8849-4F10-BB79-24BB6B5A1F15", "versionEndExcluding": "2.3.3", "versionStartIncluding": "2.3.0" }, { "criteria": "cpe:2.3:a:vmware:spring_vault:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87C49F06-1DF2-4BA5-89E4-1FD4ED9086FF", "versionEndExcluding": "3.0.2", "versionStartIncluding": "3.0.0" } ], "operator": "OR" } ] } ]