PT-2023-26552 · Unknown · Twitch-Tui
Roger
·
Published
2023-07-31
·
Updated
2023-08-09
·
CVE-2023-38688
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
twitch-tui versions prior to 2.4.1
Description
The issue arises from the software's configuration of the IRC connection, which disables TLS, resulting in unencrypted communication to Twitch IRC servers. This allows communication, including auth tokens, to be sniffed.
Recommendations
For versions prior to 2.4.1, update to version 2.4.1 to resolve the issue. As a temporary workaround, consider configuring the IRC connection to enable TLS until the update can be applied.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Twitch-Tui