oss-sec mailing list archives

CVE-2025-68637: : Insecure SSL Configuration in Uniffle HTTP Client


From: roryqi <jerqi1242949407 () gmail com>
Date: Sat, 27 Dec 2025 18:31:06 +0800

Severity:

Affected versions:

- undefined  before 0.10.0

Description:

A vulnerability.

This issue affects undefined: from before 0.10.0.

Users are recommended to upgrade to version 0.10.0, which fixes the issue.

Credit:

omkar parkhe (finder)

References:
https://uniffle.apache.orghttps://www.cve.org/CVERecord?id=CVE-2025-68637

Current thread: