Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
References
Link | Resource |
---|---|
https://gist.github.com/nyxfqq/a6da3fe6128b978ea1aaa5df639d5f98 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-07-31 21:15
Updated : 2025-03-18 18:15
NVD link : CVE-2024-41256
Mitre link : CVE-2024-41256
CVE.ORG link : CVE-2024-41256
JSON object : View
Products Affected
filestash
- filestash
CWE
CWE-295
Improper Certificate Validation