CVE-2023-29471

Publication date

2023-04-27 00:00:00

Family

mitre

State

PUBLISHED

Description

Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.