GHSA-55vq-xpjf-r2xc
Dashboard / Vulnerabilities / GHSA-55vq-xpjf-r2xc
Summary: Lightbend Alpakka Kafka logs credentials on debug level
Details: Lightbend Alpakka Kafka before 4.0.2 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-29471, https://github.com/akka/alpakka-kafka/issues/1592, https://github.com/akka/alpakka-kafka/pull/1614/commits/4011b704e93b22f6fd956aac516c7159d384644c, https://akka.io/security/alpakka-kafka-cve-2023-29471.html, https://github.com/akka/alpakka-kafka
Affected packages
Package
Name: com.typesafe.akka:akka-stream-kafka_3
Purl: pkg:maven/com.typesafe.akka/akka-stream-kafka_3
Affected ranges
Type: ECOSYSTEM
Events:
