# CVE-2023-51390

## Summary

- **CVE ID:** CVE-2023-51390
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-284, CWE-215
- **Published:** Dec 20, 2023
- **Last Modified:** Mar 13, 2026

## Description

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0.

## Affected Products

- Aiven-Open — journalpump (< 2.5.0)

## References

- [CNA](https://github.com/Aiven-Open/journalpump/security/advisories/GHSA-738v-v386-8r6g)
- [CNA](https://github.com/Aiven-Open/journalpump/commit/390e69bc909ba16ad5f7b577010b4afc303361da)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.08%
- **EPSS Percentile:** 23.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._