twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue.
References
Configurations
History
No history.
Information
Published : 2023-08-04 17:15
Updated : 2024-11-21 08:14
NVD link : CVE-2023-38688
Mitre link : CVE-2023-38688
CVE.ORG link : CVE-2023-38688
JSON object : View
Products Affected
xithrius
- twitch-tui
CWE
CWE-311
Missing Encryption of Sensitive Data