CVE-2023-51390
CVSS V2 None
CVSS V3 None
Description
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.
Overview
- CVE ID
- CVE-2023-51390
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-12-20T23:27:10.958Z
- Last Modified Date
- 2023-12-20T23:27:10.958Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/Aiven-Open/journalpump/security/advisories/GHSA-738v-v386-8r6g | x_refsource_CONFIRM |
https://github.com/Aiven-Open/journalpump/commit/390e69bc909ba16ad5f7b577010b4afc303361da | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-51390 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-51390 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 18:35:24 | Added to TrackCVE |