{"id":"CVE-2024-41255","details":"filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.","aliases":["GHSA-4jmm-c6jw-g796","GO-2024-3033"],"modified":"2026-08-12T03:51:46.592802743Z","published":"2024-07-31T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41255.json"},"references":[{"type":"WEB","url":"https://gist.github.com/nyxfqq/c367f2ca9448810924dcf0f1af30b441"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41255.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41255"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mickael-kerjean/filestash","events":[{"introduced":"0c105c1ac5197ebfcbdd7ca08cde2c7314912d7d"},{"last_affected":"0c105c1ac5197ebfcbdd7ca08cde2c7314912d7d"}],"database_specific":{"extracted_events":[{"introduced":"0.4"},{"last_affected":"0.4"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:filestash:filestash:0.4:*:*:*:*:*:*:*"}}],"versions":["0.4","v0.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41255.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}