Junglewise Threat Intelligence

CVE-2024-41265: GO-2024-3036 - cortex establishes TLS connections with `InsecureSkipVerify` set to `true` in github.com/cortexproject/cortex

CVE-2024-41265 · Severity: medium · CVSS 4 · Published 2024-08-06

Technologies: github.com/cortexproject/cortex (Go). Vendors: Go.

Executive brief

cortex establishes TLS connections with `InsecureSkipVerify` set to `true` in github.com/cortexproject/cortex

Affected products

  • Go github.com/cortexlabs/cortex
  • Go github.com/cortexproject/cortex

Related threats