CVE-2025-68637 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST…
Critical CVSS: 9.1

CVE-2025-68637

The Uniffle HTTP client is configured to trust all SSL certificates and

disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.


This issue affects all versions from before 0.10.0.

Users are recommended to upgrade to version 0.10.0, which fixes the issue.
Vendor
Apache
Product
Uniffle
CWE
CWE-297
Yayın Tarihi
2026-01-07 12:17:05
Güncelleme
2026-01-16 14:34:16
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar