PT-2023-31804 · Unknown · Journalpump

Docemmetbrown

·

Published

2023-12-20

·

Updated

2024-01-02

·

CVE-2023-51390

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions journalpump versions prior to 2.5.0
Description A logging issue was found in journalpump, where it logs the configuration of a service integration in plaintext to the supplied logging pipeline. This includes credential information contained in the configuration, if any.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the logging pipeline to minimize the risk of credential exposure.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-51390
GHSA-738V-V386-8R6G

Affected Products

Journalpump