First published: Thu Apr 27 2023(Updated: )
Lightbend Alpakka Kafka before 4.0.2 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lightbend Alpakka Kafka | <4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-29471.
Lightbend Alpakka Kafka before 4.0.2 logs its configuration as debug information, and thus log files may contain credentials if plain cleartext login is configured.
This vulnerability affects the akka.kafka.internal.KafkaConsumerActor component of Lightbend Alpakka Kafka.
The severity rating of this vulnerability is medium, with a score of 5.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
To fix this vulnerability, update to Lightbend Alpakka Kafka version 4.0.2 or higher.