PT-2017-10744 · Lightbend · Akka
Adrian Bravo
+1
·
Published
2017-07-13
·
Updated
2018-10-22
·
CVE-2017-1000034
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Akka versions <=2.4.16
Akka version 2.5-M1
Description
The issue concerns a Java deserialization attack in the Remoting component of Akka, which can result in remote code execution in the context of the ActorSystem.
Recommendations
For Akka versions <=2.4.16, update to a version greater than 2.4.16 to resolve the issue.
For Akka version 2.5-M1, update to a version greater than 2.5-M1 to resolve the issue.
As a temporary workaround, consider restricting access to the Remoting component to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Akka