PT-2024-23850 · Unknown · Dectalk-Tts

Averagehelper

·

Published

2024-04-04

·

Updated

2024-04-05

·

CVE-2024-31206

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions dectalk-tts version 1.0.0
Description The issue arises from the use of unencrypted HTTP for network requests to the third-party API in dectalk-tts@1.0.0. This allows attackers to easily intercept and modify traffic, potentially leading to man-in-the-middle (MITM) attacks. Users could be victims of such attacks, and sensitive information could be stolen if sent despite warnings. Attackers could also manipulate requests and responses, potentially returning malicious output that could endanger the user's filesystem.
Recommendations For dectalk-tts version 1.0.0, update to version 1.0.1 to resolve the issue, as the network request was upgraded to HTTPS in this version. As a precaution, do not send any sensitive information and carefully verify the API response before saving it.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31206
GHSA-6CF6-8HVR-R68W

Affected Products

Dectalk-Tts