twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1987 | twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue. |
Github GHSA |
GHSA-779w-xvpm-78jx | twitch-tui's connection is not encrypted |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:xithrius:twitch-tui:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-09T16:26:21.732Z
Reserved: 2023-07-24T16:19:28.363Z
Link: CVE-2023-38688
Updated: 2024-08-02T17:46:56.871Z
Status : Modified
Published: 2023-08-04T17:15:10.097
Modified: 2024-11-21T08:14:03.513
Link: CVE-2023-38688
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA