Akka logs environment variables

Date

2023-10-31

CVE

CVE-2023-45865

Description of Vulnerability

Environment variable values that are included in configuration are logged as plaintext when log-config-on-start is enabled in Akka. Such environment variables may contain secrets that should not be revealed.

Severity

Impact

A person with access to service logs could gain credentials.

Resolution

Environment variable values from config are not logged.

Affected versions

  • Akka up to 2.8.5

Fixed versions

  • Akka 2.9.0 and later

References