Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://github.com/akka/alpakka-kafka/issues/1592 | issue tracking |
https://akka.io/security/alpakka-kafka-cve-2023-29471.html | vendor advisory |