Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40394
HistoryMay 04, 2023 - 2:21 a.m.

Password Disclosure

2023-05-0402:21:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
52
akka-stream-kafka
password disclosure
vulnerability

0.0004 Low

EPSS

Percentile

9.0%

akka-stream-kafka is vulnerable to Password Disclosure. The vulnerability exists because it does not redact the Consumer or Producer properties in logs, which allows an attacker to read credentials as plaintext through the akka.kafka.internal.KafkaConsumerActor when debug logging is enabled.

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:40394