Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Termix has improper certificate validation in Electron desktop client that enables MITM credential/token theft
Vulnerability Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacker to intercept and modify HTTPS traffic to the configured Termix server. This can lead to credential theft and JWT/session theft during login and normal use. As of time of publication, no known patched versions are available.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
证书验证不恰当
Vulnerability Title
Termix 安全漏洞
Vulnerability Description
Termix是Karmaa个人开发者的一个服务器管理平台。 Termix 1.7.0版本及之后版本存在安全漏洞,该漏洞源于禁用TLS证书验证,可能导致中间人攻击者拦截和修改与配置的Termix服务器的HTTPS流量,导致登录和正常使用期间的凭据和JWT或会话窃取。
CVSS Information
N/A
Vulnerability Type
N/A