CVE-2023-29471
EUVD-2023-120127.04.2023, 21:15
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lightbend | alpakka_kafka | 𝑥 < 4.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration