Description
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Remediation
References
https://akka.io/security/alpakka-kafka-cve-2023-29471.html
https://github.com/akka/alpakka-kafka/issues/1592
Related Vulnerabilities
CVE-2023-50249 Vulnerability in npm package @sentry/astro
CVE-2011-3375 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2022-34213 Vulnerability in maven package org.jenkins-ci.plugins:squashtm-publisher
CVE-2020-5405 Vulnerability in maven package org.springframework.cloud:spring-cloud-config-server
CVE-2018-1000861 Vulnerability in maven package org.jenkins-ci.main:jenkins-core