CVE-2023-29471
27.04.2023, 21:15
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.Enginsight
Vendor | Product | Version |
---|---|---|
lightbend | alpakka_kafka | 𝑥 < 4.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration