ZeroHour

CVE-2023-29471

CVSS 3.1
5.5 medium
EPSS
<1%p5
Published
()
Modified
Description

Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.

Vendors
lightbend
Products
alpakka kafka
Weakness
CWE-312
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.