Description
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Remediation
References
https://akka.io/security/alpakka-kafka-cve-2023-29471.html
https://github.com/akka/alpakka-kafka/issues/1592
Related Vulnerabilities
CVE-2022-33140 Vulnerability in maven package org.apache.nifi:nifi
CVE-2016-8741 Vulnerability in maven package org.apache.qpid:qpid-broker-core
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2013-6373 Vulnerability in maven package org.jenkins-ci.plugins:exclusion
CVE-2014-0363 Vulnerability in maven package org.igniterealtime.smack:smack-core