Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2073.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Transifex command-line client 输入验证漏洞
Vulnerability Description
Transifex command-line client是Transifex团队开发的一套用于管理翻译的命令行工具。 Transifex command-line client 0.9及之前的版本中存在安全漏洞,该漏洞源于程序没有验证数据传输连接的X.509证书。攻击者可借助任意证书利用该漏洞实施中间人攻击,欺骗Transifex服务器。
CVSS Information
N/A
Vulnerability Type
N/A