Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

redhat логотип

CVE-2023-20866

больше 3 лет назад

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-20866

больше 3 лет назад

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-r7qr-f43m-pxfr

больше 3 лет назад

Spring Session session ID can be logged to the standard output stream

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-20866

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-20866

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-r7qr-f43m-pxfr

Spring Session session ID can be logged to the standard output stream

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу