VulnerabilityModified
CVE-2023-29471
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured).
MEDIUM 5.5EPSS 0.15%
Does this matter?
Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.
Description
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.15% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- lightbend/alpakka kafka
- Source
- cve@mitre.org
References
- https://akka.io/security/alpakka-kafka-cve-2023-29471.htmlVendor Advisory
- https://github.com/akka/alpakka-kafka/issues/1592Issue Tracking
- https://akka.io/security/alpakka-kafka-cve-2023-29471.htmlVendor Advisory
- https://github.com/akka/alpakka-kafka/issues/1592Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.