Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-68637

CRITICAL · 9.1 CVSS Gepubliceerd: CWE-297

Beschrijving NL

De Uniffle HTTP-client is geconfigureerd om alle SSL-certificaten en

schakelt standaard hostnaamverificatie uit. Deze onveilige configuratie
onthult alle REST API-communicatie tussen de Uniffle CLI/client en de
Uniffle Coordinator-service voor potentiële Man-in-the-Middle (MITM) -aanvallen.

Dit probleem is van invloed op alle versies van vóór 0.10.0.

Gebruikers wordt aangeraden om te upgraden naar versie 0.10.0, die het probleem oplost.

Origineel (Engels) tonen

The Uniffle HTTP client is configured to trust all SSL certificates and

disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.

This issue affects all versions from before 0.10.0.

Users are recommended to upgrade to version 0.10.0, which fixes the issue.

Vendors

Apache

Affected products

Uniffle

References