Medium severity5.9NVD Advisory· Published Jul 31, 2024· Updated Jun 17, 2026
CVE-2024-41256
CVE-2024-41256
Description
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mickael-kerjean/filestashGo | <= 0.4 | — |
Affected products
2Patches
Vulnerability mechanics
References
6- gist.github.com/nyxfqq/a6da3fe6128b978ea1aaa5df639d5f98nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-mpvx-whpp-99xjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-41256ghsaADVISORY
- github.com/mickael-kerjean/filestash/blob/master/server/model/share.goghsaWEB
- github.com/mickael-kerjean/filestash/issues/709ghsaWEB
- pkg.go.dev/vuln/GO-2024-3035ghsaWEB
News mentions
0No linked articles in our index yet.