[MAVEN:GHSA-R47R-87P9-8JH3] Spring Vault vulnerable to insertion of sensitive information into a log file

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

ID
MAVEN:GHSA-R47R-87P9-8JH3
Severity
moderate
URL
https://github.com/advisories/GHSA-r47r-87p9-8jh3
Published
2023-03-23T21:30:19
(18 months ago)
Modified
2023-03-28T18:05:35
(18 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.springframework.vault/spring-vault-core org.springframework.vault spring-vault-core < 2.3.3
Fixed pkg:maven/org.springframework.vault/spring-vault-core org.springframework.vault spring-vault-core = 2.3.3
Affected pkg:maven/org.springframework.vault/spring-vault-core org.springframework.vault spring-vault-core >= 3.0.0 < 3.0.2
Fixed pkg:maven/org.springframework.vault/spring-vault-core org.springframework.vault spring-vault-core = 3.0.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...