CVE-2024-41265
High
cortex establishes TLS connections with `InsecureSkipVerify` set to `true` in github.com/cortexproject/cortex
cortex establishes TLS connections with `InsecureSkipVerify` set to `true` in github.com/cortexproject/cortex
Exploit probability
0.3%
Published
August 6, 2024
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2024-3036
View original source
cortex establishes TLS connections with `InsecureSkipVerify` set to `true` in github.com/cortexproject/cortex
Open Source Vulnerabilities
GHSA-vw7g-3cc7-7rmh
View original source
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.
05 / REFERENCES