← Back

CVE-2024-41256

nvd nist
Published: Jul 31, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.

Affected (1)

Products: Filestash: Filestash
1 product
Filestash
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.4

References (1)

Timeline

No history available yet.