PT-2024-29333 · Filestash · Filestash

Published

2024-07-31

·

Updated

2024-08-06

·

CVE-2024-41255

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions filestash version 0.4
Description The issue is related to filestash being configured to skip TLS certificate verification when using the FTPS protocol. This could potentially allow attackers to execute a man-in-the-middle attack via the Init function of index.go.
Recommendations For filestash version 0.4, consider disabling the FTPS protocol until a patch is available that enables TLS certificate verification. Restrict access to the Init function of index.go to minimize the risk of exploitation. Avoid using the FTPS protocol in filestash until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41255
GHSA-4JMM-C6JW-G796
GO-2024-3033

Affected Products

Filestash