logo

CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping

ID: 670bbd59-67e3-5071-ae34-9135c50d49f0

STIX ID: report--670bbd59-67e3-5071-ae34-9135c50d49f0

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2025-68637, CVSS 9.1) was discovered in Apache Uniffle: the Uniffle HTTP client was shipped with insecure defaults that trust all SSL certificates and disable hostname verification, allowing Man‑in‑the‑Middle interception of REST API traffic between Uniffle clients/CLI and the Coordinator. The issue affects all Uniffle versions prior to 0.10.0; the project released version 0.10.0 to enforce certificate validation and hostname verification and administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.