CVE Vulnerabilities

CVE-2024-41255

Insecure Default Variable Initialization

Published: Jul 31, 2024 | Modified: Sep 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.

Weakness

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Affected Software

Name Vendor Start Version End Version
Filestash Filestash 0.4 (including) 0.4 (including)

Potential Mitigations

References