CVE-2025-46548 – Pekko Management Basic Authentication Misapplication

The following table lists the changes that have been made to the
CVE-2025-46548 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jun. 03, 2025

    Action Type Old Value New Value
    Added Description If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied.

    Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue.

    Added CWE CWE-287
    Added Reference https://github.com/akka/akka-management/pull/1385
    Added Reference https://github.com/apache/pekko-management/pull/418
    Added Reference https://lists.apache.org/thread/tnd84hj9w0ggjcft6cp12q67d5jzhp66
Share the Post:

Related Posts