PT-2024-23850 · Unknown · Dectalk-Tts
Averagehelper
·
Published
2024-04-04
·
Updated
2024-04-05
·
CVE-2024-31206
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
dectalk-tts version 1.0.0
Description
The issue arises from the use of unencrypted HTTP for network requests to the third-party API in
dectalk-tts@1.0.0. This allows attackers to easily intercept and modify traffic, potentially leading to man-in-the-middle (MITM) attacks. Users could be victims of such attacks, and sensitive information could be stolen if sent despite warnings. Attackers could also manipulate requests and responses, potentially returning malicious output that could endanger the user's filesystem.Recommendations
For
dectalk-tts version 1.0.0, update to version 1.0.1 to resolve the issue, as the network request was upgraded to HTTPS in this version.
As a precaution, do not send any sensitive information and carefully verify the API response before saving it.Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dectalk-Tts