Akka is vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem. External References: http://doc.akka.io/docs/akka/2.4/security/2017-02-10-java-serialization.html
Created opendaylight tracking bugs for this issue: Affects: openstack-rdo [bug 1484951]
In RHOS 12 ODL, we're shipping Akka 2.4.18, which doesn't suffer from this issue.