PT-2024-29333 · Filestash · Filestash
Published
2024-07-31
·
Updated
2024-08-06
·
CVE-2024-41255
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
filestash version 0.4
Description
The issue is related to filestash being configured to skip TLS certificate verification when using the FTPS protocol. This could potentially allow attackers to execute a man-in-the-middle attack via the
Init function of index.go.Recommendations
For filestash version 0.4, consider disabling the FTPS protocol until a patch is available that enables TLS certificate verification. Restrict access to the
Init function of index.go to minimize the risk of exploitation. Avoid using the FTPS protocol in filestash until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filestash