GHSA-r47r-87p9-8jh3
MODERATECVE-2023-20859In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
- Affected
- < 2.3.3, >= 3.0.0, < 3.0.2
- Fixed in
- 2.3.3
- Weakness
- CWE-532
- Published
- 2023-03-23
- Source
- github