CVE-2024-41255Medium· 5.9▾ SunlitFilestash configured to skip TLS certificate verification when using the FTPS protocol
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
github.com/mickael-kerjean/filestash <= 0.4Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.