Description
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Remediation
References
https://akka.io/security/alpakka-kafka-cve-2023-29471.html
https://github.com/akka/alpakka-kafka/issues/1592
Related Vulnerabilities
CVE-2022-41246 Vulnerability in maven package org.jenkins-ci.plugins:ws-execution-manager
CVE-2021-21618 Vulnerability in maven package org.jenkins-ci.plugins:repository-connector
CVE-2014-3625 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2020-17532 Vulnerability in maven package org.apache.servicecomb:foundation-config
CVE-2019-17563 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core