CVE-2025-68637
Beschrijving NL
De Uniffle HTTP-client is geconfigureerd om alle SSL-certificaten en
schakelt standaard hostnaamverificatie uit. Deze onveilige configuratie
onthult alle REST API-communicatie tussen de Uniffle CLI/client en de
Uniffle Coordinator-service voor potentiële Man-in-the-Middle (MITM) -aanvallen.
Dit probleem is van invloed op alle versies van vóór 0.10.0.
Gebruikers wordt aangeraden om te upgraden naar versie 0.10.0, die het probleem oplost.
Origineel (Engels) tonen
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.
This issue affects all versions from before 0.10.0.
Users are recommended to upgrade to version 0.10.0, which fixes the issue.