CVE-2024-41253 Information

Description

goframe v2.7.2 is configured to skip TLS certificate verification possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.

Reference

https://gist.github.com/nyxfqq/f69d41c69a4d0751841f4d972b9745da

Share on: