High severity7.5NVD Advisory· Published Jul 31, 2024· Updated Jun 17, 2026
CVE-2024-41255
CVE-2024-41255
Description
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mickael-kerjean/filestashGo | <= 0.4 | — |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-4jmm-c6jw-g796ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-41255ghsaADVISORY
- gist.github.com/nyxfqq/c367f2ca9448810924dcf0f1af30b441nvdBroken LinkWEB
- github.com/mickael-kerjean/filestash/blob/master/server/plugin/plg_backend_ftp/index.goghsaWEB
- github.com/mickael-kerjean/filestash/issues/710ghsaWEB
- pkg.go.dev/vuln/GO-2024-3033ghsaWEB
News mentions
0No linked articles in our index yet.