Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-51390


journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.


Published

2023-12-21T00:15:26.163

Last Modified

2024-11-21T08:38:00.733

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-215
    CWE-284
  • Type: Primary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application aiven journalpump < 2.5.0 Yes

References