CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. See the original NVD description below for full technical details.
CVE
CVE-2023-20866
Severity
MEDIUM
CVSS
6.5
EPSS
0.66%
Original NVD Description
In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.
Related CVEs
Other vulnerabilities affecting the same vendor(s)