Apache Pekko Management Basic Authentication Vulnerability

Vulnerability

A vulnerability exists in Apache Pekko Management versions 1.0.0 prior to 1.1.1, across multiple Scala versions, including 2.12, 2.13, and 3. This issue arises when Basic Authentication is enabled via the Java DSL; the authenticator may not be applied correctly. As a result, users relying on authentication should upgrade to version 1.1.1, which addresses this problem.

Impact

This vulnerability can lead to ineffective authentication, allowing unauthorized access to the Management API.

Remediation

Users are advised to upgrade to Apache Pekko Management version 1.1.1.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.