GHSA-mpvx-whpp-99xj

Suggest an improvement
Source
https://github.com/advisories/GHSA-mpvx-whpp-99xj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-mpvx-whpp-99xj/GHSA-mpvx-whpp-99xj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mpvx-whpp-99xj
Aliases
Published
2024-07-31T21:32:38Z
Modified
2024-08-07T19:27:52Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Filestash skips TLS certificate verification process when sending out email verification codes
Details

Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.

Database specific
{
    "nvd_published_at": "2024-07-31T21:15:18Z",
    "cwe_ids": [
        "CWE-295"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-08-02T16:40:57Z"
}
References

Affected packages

Go / github.com/mickael-kerjean/filestash

Package

Name
github.com/mickael-kerjean/filestash
View open source insights on deps.dev
Purl
pkg:golang/github.com/mickael-kerjean/filestash

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.4