CVE-2023-51390
Last modified
CVE-2023-51390 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Aiven | Journalpump | < 2.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-51390?
How severe is CVE-2023-51390?
How do I fix CVE-2023-51390?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-51385In ssh in OpenSSH before 9.6, OS command injection might occ…6.5
- CVE-2023-51386Sandbox Accounts for Events provides multiple, temporary AWS…3.3
- CVE-2023-51387Hertzbeat is an open source, real-time monitoring system. He…8.8
- CVE-2023-51388Hertzbeat is a real-time monitoring system. In `CalculateAla…9.8
- CVE-2023-51389Hertzbeat is a real-time monitoring system. At the interface…9.8
- CVE-2023-5139Potential buffer overflow vulnerability at the following loc…7.8
- CVE-2023-51391A bug in Micrium OS Network HTTP Server permits an invalid p…7.5
- CVE-2023-51392Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM i…9.8
- CVE-2023-51393Due to an allocation of resources without limits, an uncontr…7.5
- CVE-2023-51394High traffic environments may result in NULL Pointer Derefer…7.5
- CVE-2023-51395The vulnerability described by CVE-2023-0972 has been additi…8.8
- CVE-2023-51396Improper Neutralization of Input During Web Page Generation …5.4
Are you affected by CVE-2023-51390?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
