Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29471


Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.


Published

2023-04-27T21:15:10.710

Last Modified

2025-01-31T19:15:13.353

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-312
  • Type: Secondary
    CWE-312

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application lightbend alpakka_kafka < 4.0.2 Yes

References