PT-2023-17679 · Spring · Spring Vault

Martin Kiesel

·

Publicado

2023-03-23

·

Atualizado

2023-03-28

·

CVE-2023-20859

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spring Vault versions 2.3.x prior to 2.3.3 Spring Vault versions 3.0.x prior to 3.0.2
Description The application is vulnerable to the insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
Recommendations For versions 2.3.x prior to 2.3.3, update to version 2.3.3 or later. For versions 3.0.x prior to 3.0.2, update to version 3.0.2 or later. As a temporary workaround, consider restricting access to the log files to minimize the risk of sensitive information exposure.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-20859
GHSA-R47R-87P9-8JH3

Produtos afetados

Spring Vault