logo

CVE-2025-46548 org.apache.pekko:pekko-management_3

Package

Manager: maven
Name: org.apache.pekko:pekko-management_3
Vulnerable Version: >=0 <1.1.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00592 pctl0.68297

Details

Pekko Management may not properly apply authenticator when Basic Authentication enabled If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue.

Metadata

Created: 2025-06-03T15:31:27Z
Modified: 2025-06-06T15:33:33Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json
CWE IDs: ["CWE-287"]
Alternative ID: GHSA-9qvj-rpj8-v5c8
Finding: F006
Auto approve: 1