Description
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Remediation
References
https://akka.io/security/alpakka-kafka-cve-2023-29471.html
https://github.com/akka/alpakka-kafka/issues/1592
Related Vulnerabilities
CVE-2020-2120 Vulnerability in maven package org.jenkins-ci.plugins:fitnesse
CVE-2020-2201 Vulnerability in maven package org.jenkins-ci.plugins:sonargraph-integration
CVE-2013-4517 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2017-1000387 Vulnerability in maven package org.jenkins-ci.plugins:build-publisher
CVE-2019-12421 Vulnerability in maven package org.apache.nifi:nifi-administration