CVE-2023-29471: Medium severity lightbend alpakka kafka vulnerability
Lightbend Alpakka Kafka before 4.0.2 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Other sources
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-29471.
How does Lightbend Alpakka Kafka before 4.0.2 expose credentials?
Lightbend Alpakka Kafka before 4.0.2 logs its configuration as debug information, and thus log files may contain credentials if plain cleartext login is configured.
Which component of Lightbend Alpakka Kafka is affected by this vulnerability?
This vulnerability affects the akka.kafka.internal.KafkaConsumerActor component of Lightbend Alpakka Kafka.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium, with a score of 5.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
How can I fix this vulnerability?
To fix this vulnerability, update to Lightbend Alpakka Kafka version 4.0.2 or higher.