Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-31442: Lightbend | Power Your Innovation with Cloud Native Applications | @lightbend

In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making DNS resolution subject to poisoning by an attacker. If the application performing discovery does not validate (e.g., via TLS) the authenticity of the discovered service, this may result in exfiltration of application data (e.g., persistence events may be published to an unintended Kafka broker). If such validation is performed, then the poisoning constitutes a denial of access to the intended service. This affects Akka 2.5.14 through 2.8.0, and Akka Discovery through 2.8.0.

CVE
#web#git#pdf#auth#ssl

Achieve Success with Lightbend****Lightbend solutions help virtually any industry or vertical bring their digital strategies to life.

What’s New(s)

AWARD****Frost & Sullivan—2022 Company of the Year

Lightbend/Kalix has been named by Frost & Sullivan as the recipient of the 2022 North American Serverless Computing Company of the Year Award.

Read More (PDF)

Kalix Webinars****Catch up with On-Demand Webinars

Check out our latest webinars on-demand over at Kalix.io. Hear from Lightbend luminaries and learn how Kalix removes the hurdles of distributed data, distributed systems and all underlying architecture complexity.

Watch Now

Akka delivers the scalability and resiliency required to handle our current number of participants and expected growth.

READ CASE STUDY

For core financial transactional systems where data quality and consistency are paramount, we strongly recommend Akka.

READ CASE STUDY

Akka has enabled Tubi to provide customer experiences unlike any other in the video-on-demand space.

READ CASE STUDY

We’ve cut software development costs by 30% and our hardware costs by 50%—helping us to offer highly competitive pricing.

READ CASE STUDY

Strategic Partners Powered by Lightbend

Talk to an Expert

We’d love to learn about your requirements, answer your unique questions, and review ways that Lightbend can help you and your organization.

Contact Us

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907