CVE-2023-51390

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aiven:journalpump:*:*:*:*:*:*:*:*

History

02 Jan 2024, 16:25

Type Values Removed Values Added
References () https://github.com/Aiven-Open/journalpump/commit/390e69bc909ba16ad5f7b577010b4afc303361da - () https://github.com/Aiven-Open/journalpump/commit/390e69bc909ba16ad5f7b577010b4afc303361da - Patch
References () https://github.com/Aiven-Open/journalpump/security/advisories/GHSA-738v-v386-8r6g - () https://github.com/Aiven-Open/journalpump/security/advisories/GHSA-738v-v386-8r6g - Vendor Advisory
First Time Aiven journalpump
Aiven
CWE CWE-319
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:aiven:journalpump:*:*:*:*:*:*:*:*

21 Dec 2023, 02:24

Type Values Removed Values Added
Summary
  • (es) journalpump es un daemon que toma mensajes de registro de journald y los envía a una salida determinada. Se encontró una vulnerabilidad de registro en journalpump que registra la configuración de una integración de servicios en texto plano en la canalización de registro proporcionada, incluida la información de credenciales contenida en la configuración, si corresponde. El problema se solucionó en journalpump 2.5.0.

21 Dec 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-21 00:15

Updated : 2024-01-02 16:25


NVD link : CVE-2023-51390

Mitre link : CVE-2023-51390

CVE.ORG link : CVE-2023-51390


JSON object : View

Products Affected

aiven

  • journalpump
CWE
CWE-319

Cleartext Transmission of Sensitive Information

CWE-215

Insertion of Sensitive Information Into Debugging Code

CWE-284

Improper Access Control