Vulnerability Description
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aiven | Journalpump | < 2.5.0 |
Related Weaknesses (CWE)
References
- https://github.com/Aiven-Open/journalpump/commit/390e69bc909ba16ad5f7b577010b4afPatch
- https://github.com/Aiven-Open/journalpump/security/advisories/GHSA-738v-v386-8r6Vendor Advisory
- https://github.com/Aiven-Open/journalpump/commit/390e69bc909ba16ad5f7b577010b4afPatch
- https://github.com/Aiven-Open/journalpump/security/advisories/GHSA-738v-v386-8r6Vendor Advisory
FAQ
What is CVE-2023-51390?
CVE-2023-51390 is a vulnerability with a CVSS score of 6.5 (MEDIUM). journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integrati...
How severe is CVE-2023-51390?
CVE-2023-51390 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-51390?
Check the references section above for vendor advisories and patch information. Affected products include: Aiven Journalpump.