Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Filestash
Filestash filestash |
|
Weaknesses | CWE-295 | |
CPEs | cpe:2.3:a:filestash:filestash:*:*:*:*:*:*:*:* | |
Vendors & Products |
Filestash
Filestash filestash |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-31T00:00:00
Updated: 2024-08-01T15:02:10.422Z
Reserved: 2024-07-18T00:00:00
Link: CVE-2024-41256
Vulnrichment
Updated: 2024-08-01T15:02:05.816Z
NVD
Status : Analyzed
Published: 2024-07-31T21:15:18.117
Modified: 2024-08-15T14:27:18.487
Link: CVE-2024-41256
Redhat
No data.