CVE-2023-51390

MEDIUM

journalpump <2.5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 19.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-284 CWE-319 CWE-215
Status published
Products (1)
aiven/journalpump < 2.5.0
Published Dec 21, 2023
Tracked Since Feb 18, 2026