In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
| Software | From | Fixed in |
|---|---|---|
| vmware / spring_vault | 3.0.0 | 3.0.2 |
| vmware / spring_vault | 2.3.0 | 2.3.3 |
| vmware / spring_cloud_vault | 4.0.0 | 4.0.0.x |
| vmware / spring_cloud_config | 4.0.0 | 4.0.1.x |
| vmware / spring_cloud_config | 3.1.0 | 3.1.6.x |
| vmware / spring_cloud_vault | 3.1.0 | 3.1.2.x |
org.springframework.vault / spring-vault-core
|
3.0.0 | 3.0.2 |
org.springframework.vault / spring-vault-core
|
- | 2.3.3 |