CVE Database
/

CVE-2025-46548

Back to search

CVE-2025-46548

Published: Jun 3, 2025

Modified: Jun 11, 2025

PUBLISHED

Description

If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1.

VendorProductVersions

Apache Software Foundation

Apache Pekko Management

affected
1.0.0 - < 1.1.1

Apache Software Foundation

Apache Pekko Management

affected
1.0.0 - < 1.1.1

Apache Software Foundation

Apache Pekko Management

affected
1.0.0 - < 1.1.1

Lightbend

Akka Management

affected
0 - < 1.6.1

Lightbend

Akka Management

affected
0 - < 1.6.1

Lightbend

Akka Management

affected
0 - < 1.6.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-46548 - Security Vulnerability | QwikSec