CVE-2023-29471

MEDIUM

Lightbend Alpakka Kafka < 5.0.0 - Cleartext Storage of Sensitive Information in Debug Logs

Title source: llm
STIX 2.1

Description

Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (5)
com.typesafe.akka/akka-stream-kafka_2.11 0Maven
com.typesafe.akka/akka-stream-kafka_2.12 0 - 4.0.2Maven
com.typesafe.akka/akka-stream-kafka_2.13 0 - 4.0.2Maven
com.typesafe.akka/akka-stream-kafka_3 0 - 4.0.2Maven
lightbend/alpakka_kafka < 4.0.2
Published Apr 27, 2023
Tracked Since Feb 18, 2026