Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAOCXXtuV5_qg6kkC92qMe_nrjeyM2OLUdgVi0CSRvj6ax0cRkA@mail.gmail.com>
Date: Sat, 27 Dec 2025 18:31:06 +0800
From: roryqi <jerqi1242949407@...il.com>
To: oss-security@...ts.openwall.com, dev@...ffle.apache.org, 
	omkar parkhe <omkarparth@...il.com>, announce@...che.org, security@...che.org
Subject: CVE-2025-68637: : Insecure SSL Configuration in Uniffle HTTP Client

Severity:

Affected versions:

- undefined  before 0.10.0

Description:

A vulnerability.

This issue affects undefined: from before 0.10.0.

Users are recommended to upgrade to version 0.10.0, which fixes the issue.

Credit:

omkar parkhe (finder)

References:
https://uniffle.apache.orghttps://www.cve.org/CVERecord?id=CVE-2025-68637

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.