Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
History

Thu, 15 Aug 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Filestash
Filestash filestash
Weaknesses CWE-295
CPEs cpe:2.3:a:filestash:filestash:*:*:*:*:*:*:*:*
Vendors & Products Filestash
Filestash filestash
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-07-31T00:00:00

Updated: 2024-08-01T15:02:10.422Z

Reserved: 2024-07-18T00:00:00

Link: CVE-2024-41256

cve-icon Vulnrichment

Updated: 2024-08-01T15:02:05.816Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-31T21:15:18.117

Modified: 2024-08-15T14:27:18.487

Link: CVE-2024-41256

cve-icon Redhat

No data.