Description
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
Remediation
References
https://spring.io/security/cve-2023-20859
Related Vulnerabilities
CVE-2020-10199 Vulnerability in maven package org.sonatype.nexus:nexus-extdirect
CVE-2022-42129 Vulnerability in maven package com.liferay:com.liferay.dynamic.data.mapping.form.web
CVE-2015-1813 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-6341 Vulnerability in maven package org.webjars.bowergithub.vuejs:vue
CVE-2019-20903 Vulnerability in npm package @atlaskit/editor-core