If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied.
Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue.
Akka was affected by the same issue and has released the fix in version 1.6.1.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1. |
Title | Apache Pekko Management, Apache Pekko Management, Apache Pekko Management: management API basic authentication is not effective | Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effective |
Wed, 04 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 04 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 03 Jun 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. | |
Title | Apache Pekko Management, Apache Pekko Management, Apache Pekko Management: management API basic authentication is not effective | |
Weaknesses | CWE-287 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-06-03T14:45:32.890Z
Updated: 2025-06-11T17:44:23.190Z
Reserved: 2025-04-24T20:07:58.395Z
Link: CVE-2025-46548

Updated: 2025-06-03T18:03:45.963Z

Status : Awaiting Analysis
Published: 2025-06-03T15:15:59.110
Modified: 2025-06-11T16:15:24.307
Link: CVE-2025-46548

No data.