CVE-2023-20859: VMware Spring Cloud Config

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

Affected products

  • VMware Spring Cloud Config: from 3.1.0, up to and including 3.1.6; from 4.0.0, up to and including 4.0.1
  • VMware Spring Cloud Vault: from 3.1.0, up to and including 3.1.2; version 4.0.0 only
  • VMware Spring Vault: from 2.3.0, before 2.3.3 (fixed in 2.3.3); from 3.0.0, before 3.0.2 (fixed in 3.0.2)

Published 2023-03-23. Last modified 2026-06-17.