filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filestash
Filestash filestash |
|
| CPEs | cpe:2.3:a:filestash:filestash:0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Filestash
Filestash filestash |
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-31T00:00:00
Updated: 2024-08-01T14:45:04.150Z
Reserved: 2024-07-18T00:00:00
Link: CVE-2024-41255
Updated: 2024-08-01T14:43:30.689Z
Status : Analyzed
Published: 2024-07-31T21:15:18.030
Modified: 2025-09-29T14:08:17.620
Link: CVE-2024-41255
No data.