Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
{
"severity": "HIGH",
"cwe_ids": [
"CWE-502"
],
"nvd_published_at": null,
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:46:32Z"
}