CVE-2023-38688
Summary
| CVE | CVE-2023-38688 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-04 17:15:00 UTC |
| Updated | 2023-08-09 21:05:00 UTC |
| Description | twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xithrius | Twitch-tui | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/Xithrius/twitch-tui/blob/340afc3c8c07a83289fe6ef614aa7563c8b7... | MISC | github.com | |
| Enable SSL for the Twitch IRC connection. · Xithrius/twitch-tui@74d13dd · GitHub | MISC | github.com | |
| Connection is not encrypted · Advisory · Xithrius/twitch-tui · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.