CVE-2024-41255: Filestash
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
Affected products
- Filestash Filestash: version 0.4 only
Published 2024-07-31. Last modified 2026-06-17.