Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2386 | Filestash skips TLS certificate verification process when sending out email verification codes |
Github GHSA |
GHSA-mpvx-whpp-99xj | Filestash skips TLS certificate verification process when sending out email verification codes |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 15 Aug 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filestash
Filestash filestash |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:filestash:filestash:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Filestash
Filestash filestash |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-18T17:59:41.550Z
Reserved: 2024-07-18T00:00:00.000Z
Link: CVE-2024-41256
Updated: 2024-08-01T15:02:05.816Z
Status : Modified
Published: 2024-07-31T21:15:18.117
Modified: 2025-03-18T18:15:27.097
Link: CVE-2024-41256
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA