In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
{
"versions": [
{
"introduced": "3.1.0"
},
{
"last_affected": "3.1.6"
},
{
"introduced": "4.0.0"
},
{
"last_affected": "4.0.1"
},
{
"introduced": "3.1.0"
},
{
"last_affected": "3.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0"
},
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.2"
}
]
}