CVE-2023-29471: Lightbend Alpakka Kafka
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Affected products
- Lightbend Alpakka Kafka: before 4.0.2 (fixed in 4.0.2)
Published 2023-04-27. Last modified 2026-06-17.