Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
twitch-tui's connection is not encrypted
Vulnerability Description
twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
敏感数据加密缺失
Vulnerability Title
twitch-tui 安全漏洞
Vulnerability Description
twitch-tui是Xithrius个人开发者的一个终端聊天应用程序。 twitch-tui 存在安全漏洞,该漏洞源于在 irc 连接的配置中,该软件禁用了 TLS,这导致与 Twitch IRC 服务器之间的所有通信都是未加密的。
CVSS Information
N/A
Vulnerability Type
N/A