CVE-2023-29471
Lightbend Alpakka Kafka logs credentials on debug level
5.5
MEDIUM
CVSS 3.1
EPSS 0.06%
Description
Lightbend Alpakka Kafka before 4.0.2 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
How to fix CVE-2023-29471
To remediate CVE-2023-29471, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 4.0.2 or later
- —upgrade to 4.0.2 or later
- —upgrade to 4.0.2 or later
Is CVE-2023-29471 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0
- from 0, < 4.0.2
- from 0, < 4.0.2
- from 0, < 4.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |