CVE-2023-51390: Information Disclosure Vulnerability in Journalpump

Published Dec 20, 2023
·
Updated

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.

Affected Software

1 affected component
aiven Journalpump<2.5.0

Event History

Dec 20, 2023
CVE Published
11:27 PM
Data Sourced
11:27 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2023-51390?

CVE-2023-51390 is considered to be a moderate severity vulnerability due to the potential exposure of sensitive credential information.

2

How do I fix CVE-2023-51390?

To fix CVE-2023-51390, upgrade journalpump to version 2.5.0 or later to ensure that credential information is not logged in plaintext.

3

What types of systems are affected by CVE-2023-51390?

CVE-2023-51390 affects versions of Aiven Journalpump prior to 2.5.0.

4

Is credential data at risk due to CVE-2023-51390?

Yes, CVE-2023-51390 logs configuration details, which may include credential information, in plaintext.

5

Can CVE-2023-51390 lead to data breaches?

Yes, if exploited, CVE-2023-51390 could lead to data breaches due to the exposure of sensitive credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203