Alist Application Vulnerable to MitM Attacks
The Alist application appears to disable TLS certificate verification by default for all outgoing storage driver communications, making it vulnerable to Man-in-the-Middle (MitM) attacks. This could allow decryption, theft, and manipulation of data during storage operations.
What happened
According to the GitHub Security Advisory GHSA-8jmm-3xwx-w974, the Alist application is under investigation for an insecure TLS configuration. It is reported that Alist disables TLS certificate verification by default for all outgoing storage driver communications. This configuration reportedly makes the system vulnerable to Man-in-the-Middle (MitM) attacks, potentially allowing attackers to decrypt, steal, and manipulate all data transmitted during storage operations. This severely compromises the confidentiality and integrity of user data.
To assess your exposure, check if your deployment of Alist has the default TLS configuration. If so, it is recommended to upgrade to a version of Alist that enables TLS certificate verification or apply a patch to enable verification. For more detailed information, consult the primary sources, particularly the GitHub Security Advisory GHSA-8jmm-3xwx-w974.
How 0Day mitigates this
alist is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.