External risk intelligence

Uniffle HTTP Client Vulnerable to Man-in-the-Middle Attacks

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-68637

Uniffle is a remote shuffle service for Apache Spark and MapReduce, typically deployed within internal data center networks or private clusters to facilitate data processing. While it communicates over a network, it is not designed to be exposed directly to the public internet, making public-facing deployment uncommon.

Apache Uniffle

before 0.10.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The Uniffle HTTP client has a security vulnerability related to how it handles SSL certificates and verifies server identities. This could allow attackers to intercept and potentially alter communications between Uniffle components, impacting data integrity and confidentiality. The main concern is confirming relevance and exposure.

  • Insecure Uniffle communication can be intercepted.
  • Protects data integrity and confidentiality.
  • Confirm if Uniffle is used and exposed.

Attack Path

How an attacker could exploit the issue

An attacker could intercept communications between a Uniffle client and the Uniffle Coordinator by exploiting the client's default SSL configuration, which trusts all certificates and skips hostname verification. This allows them to perform a Man-in-the-Middle attack, potentially leading to the disclosure or manipulation of sensitive data exchanged during REST API calls.

  • Network exposure required.
  • Uniffle HTTP client insecure configuration.
  • Man-in-the-Middle data interception.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, communication between the Uniffle HTTP client and its Coordinator service could be intercepted and modified by an attacker. This may expose sensitive information or allow for unauthorized actions when the client and service are communicating.

  • REST API communication.
  • Man-in-the-Middle attacks.
  • Data exposure and unauthorized actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership

The Uniffle HTTP client's default configuration of trusting all SSL certificates and disabling hostname verification creates a significant risk of Man-in-the-Middle attacks on REST API communications. This issue is likely to impact platform or data engineering teams responsible for managing Uniffle deployments, as well as security teams responsible for network and API security. The first practical step is for these teams to identify all Uniffle instances, assess their network exposure and business criticality, and then coordinate remediation efforts, prioritizing instances that are externally reachable or critical to business operations.

  • Platform and security teams own resolution.
  • Verify Uniffle deployment exposure and criticality.
  • Plan coordinated updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Uniffle?

Apache Uniffle is a remote shuffle service designed to handle data shuffling for large-scale distributed computing frameworks like Apache Spark and MapReduce. It optimizes data processing performance by decoupling the shuffle data management from the compute engines, allowing tasks to write data to a centralized cluster of Uniffle servers instead of local disks.

What does CVE-2025-68637 mean for Uniffle security?

This CVE describes a flaw classified as CWE-297, which involves improper validation of certificates. Essentially, the Uniffle HTTP client does not verify that an SSL certificate belongs to the server it is talking to, nor does it check the server's hostname. This failure allows an attacker to masquerade as the Uniffle Coordinator, enabling them to intercept, view, or modify the data sent between the client and the coordinator during API requests.

How does an attacker trigger this vulnerability?

An attacker triggers this by positioning themselves in the network path between a Uniffle client and the Uniffle Coordinator to conduct a Man-in-the-Middle attack. It is important to note that this is not a remote code execution bug; simply sending malformed packets to the service will not trigger the flaw. The vulnerability specifically relies on the client's insecure default setting to blindly trust any presented certificate during the connection handshake.

Do I need to worry if my Uniffle instance is not on the internet?

According to Halo Surface Signal, Uniffle is typically used within private data center networks or clusters for internal processing, making public-facing deployments uncommon. While an internal placement reduces the risk of external attackers reaching the service, you should still evaluate if an attacker who has already breached your internal network could move laterally to intercept these communications.

How should I respond to CVE-2025-68637?

Your first step is to audit your environment to identify all instances running Uniffle versions prior to 0.10.0. Once identified, prioritize these for an upgrade to version 0.10.0, which resolves the insecure SSL configuration. Coordinate this maintenance with your data engineering or platform teams to ensure that the update is applied without disrupting your active data processing jobs.

References