If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1.
History

Wed, 11 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Description If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1.
Title Apache Pekko Management, Apache Pekko Management, Apache Pekko Management: management API basic authentication is not effective Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effective

Wed, 04 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
References

Tue, 03 Jun 2025 15:00:00 +0000

Type Values Removed Values Added
Description If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue.
Title Apache Pekko Management, Apache Pekko Management, Apache Pekko Management: management API basic authentication is not effective
Weaknesses CWE-287
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-06-03T14:45:32.890Z

Updated: 2025-06-11T17:44:23.190Z

Reserved: 2025-04-24T20:07:58.395Z

Link: CVE-2025-46548

cve-icon Vulnrichment

Updated: 2025-06-03T18:03:45.963Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-03T15:15:59.110

Modified: 2025-06-11T16:15:24.307

Link: CVE-2025-46548

cve-icon Redhat

No data.