VulnerabilityModified
CVE-2023-20866
This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking.
MEDIUM 6.5EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- vmware/spring session
- Source
- security@vmware.com
References
- https://spring.io/security/cve-2023-20866Vendor Advisory
- https://spring.io/security/cve-2023-20866Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.