Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-779w-xvpm-78jx

Опубликовано: 31 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

twitch-tui's connection is not encrypted

Summary

The connection is not using TLS for communication

Details

In the configuration of the irc connection, you are disabling tls which makes all communication to twitch irc servers unencrypted.

PoC

You can verify by using tcpdump/wireshark that traffic is unencrypted.

Impact

Communication can be sniffed, even auth tokens.

Пакеты

Наименование

twitch-tui

rust
Затронутые версииВерсия исправления

< 2.4.1

2.4.1

EPSS

Процентиль: 70%
0.00643
Низкий

7.5 High

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue.

EPSS

Процентиль: 70%
0.00643
Низкий

7.5 High

CVSS3

Дефекты

CWE-311