CVE-2024-41256

MEDIUM

filestash < 0.4 - Improper Certificate Validation in ShareProofVerifier

Title source: llm
STIX 2.1

Description

Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0021
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (2)
filestash/filestash < 0.4
mickael-kerjean/filestash 0Go
Published Jul 31, 2024
Tracked Since Feb 18, 2026