Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.typesafe.akka:akka-stream-kafka_3(Maven) | 0 | 4.0.2 | N/A |
| com.typesafe.akka:akka-stream-kafka_2.13(Maven) | 0 | 4.0.2 | N/A |
| com.typesafe.akka:akka-stream-kafka_2.12(Maven) | 0 | 4.0.2 | N/A |
| com.typesafe.akka:akka-stream-kafka_2.11(Maven) | 0 | N/A | N/A |
CVSS Metrics