Vulnerability Description
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Akka | Akka | <= 2.4.16 |
Related Weaknesses (CWE)
References
- http://doc.akka.io/docs/akka/2.4/security/2017-02-10-java-serialization.htmlVendor Advisory
- http://doc.akka.io/docs/akka/2.4/security/2017-02-10-java-serialization.htmlVendor Advisory
FAQ
What is CVE-2017-1000034?
CVE-2017-1000034 is a vulnerability with a CVSS score of 8.1 (HIGH). Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
How severe is CVE-2017-1000034?
CVE-2017-1000034 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000034?
Check the references section above for vendor advisories and patch information. Affected products include: Akka Akka.