Description
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Remediation
References
https://akka.io/security/alpakka-kafka-cve-2023-29471.html
https://github.com/akka/alpakka-kafka/issues/1592
Related Vulnerabilities
CVE-2018-12538 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2023-50766 Vulnerability in maven package org.sonatype.nexus.ci:nexus-jenkins-plugin
CVE-2022-36918 Vulnerability in maven package org.jenkins-ci.plugins:buckminster
CVE-2014-3656 Vulnerability in maven package org.keycloak:keycloak-services