CVE-2023-20866

MEDIUM

Spring Session 3.0.0 - Exposure of Sensitive Information via Session ID Logging

Title source: llm
STIX 2.1

Description

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0072
EPSS Percentile 72.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
org.springframework.session/spring-session-core 3.0.0 - 3.0.1Maven
vmware/spring_session 3.0.0
Published Apr 13, 2023
Tracked Since Feb 18, 2026