PT-2024-29341 · Cortex · Cortex

Yuexi Zhang

·

Published

2024-08-01

·

Updated

2026-01-06

·

CVE-2024-41265

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cortex version 0.42.1
Description A TLS certificate verification issue allows attackers to obtain sensitive information via the makeOperatorRequest function. This is due to cortex establishing TLS connections with the InsecureSkipVerify variable set to true.
Recommendations For cortex version 0.42.1, consider disabling the makeOperatorRequest function until a patch is available, and restrict the use of InsecureSkipVerify to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-41265
GHSA-VW7G-3CC7-7RMH
GO-2024-3036
SUSE-SU-2026:0037-1

Affected Products

Cortex