Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.typesafe.akka:akka-actor(Maven) | 0 | 2.4.17 | N/A |
CVSS Metrics