{"id":"CVE-2017-1000034","details":"Akka versions \u003c=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.","aliases":["GHSA-mm57-9j6q-rxm2"],"modified":"2026-08-27T08:18:45.746773Z","published":"2017-07-17T13:18:17.047Z","references":[{"type":"ADVISORY","url":"http://doc.akka.io/docs/akka/2.4/security/2017-02-10-java-serialization.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/akka/akka-core","events":[{"introduced":"0"},{"last_affected":"7a79595c6410ab5b02061e954edb9cc43d467bad"},{"introduced":"f2ca4e18668319f46216e8a356e3453fb66ad4e6"},{"last_affected":"f2ca4e18668319f46216e8a356e3453fb66ad4e6"}],"database_specific":{"cpe":["cpe:2.3:a:akka:akka:*:*:*:*:*:*:*:*","cpe:2.3:a:akka:akka:2.5:m1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.4.16"},{"introduced":"2.5-m1"},{"last_affected":"2.5-m1"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.5-m1","v2.5.1","v2.4.16","master-pre-2.10","v0.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000034.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}