Headline
GHSA-4jmm-c6jw-g796: Filestash configured to skip TLS certificate verification when using the FTPS protocol
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
Filestash configured to skip TLS certificate verification when using the FTPS protocol
High severity GitHub Reviewed Published Jul 31, 2024 to the GitHub Advisory Database • Updated Aug 2, 2024