Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mpvx-whpp-99xj: Filestash skips TLS certificate verification process when sending out email verification codes

Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.

ghsa
#git#ssl

Filestash skips TLS certificate verification process when sending out email verification codes

High severity GitHub Reviewed Published Jul 31, 2024 to the GitHub Advisory Database • Updated Aug 2, 2024

ghsa: Latest News

GHSA-hxf5-99xg-86hw: cap-std doesn't fully sandbox all the Windows device filenames