Description
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Remediation
References
https://akka.io/security/alpakka-kafka-cve-2023-29471.html
https://github.com/akka/alpakka-kafka/issues/1592
Related Vulnerabilities
CVE-2017-2613 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10240 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-parent
CVE-2019-12404 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2022-41230 Vulnerability in maven package org.jenkins-ci.plugins:build-publisher
CVE-2018-11537 Vulnerability in maven package org.webjars:angular-jwt