← Back

CVE-2025-46548

nvd nist
Published: Jun 3, 2025Modified: Jul 2, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1.

Affected (2)

1 product
Pekko Management
1 product
Akka Management
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.1.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.6.1

References (4)

Source: security@apache.org
ExploitIssue Tracking
Source: security@apache.org
Issue TrackingPatch
Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.