CVE-2023-38688

HIGH

twitch-tui <2.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC servers unencrypted. As a result, communication, including auth tokens, can be sniffed. Version 2.4.1 has a patch for this issue.

Scores

CVSS v3 7.5
EPSS 0.0071
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-311
Status published
Products (2)
crates.io/twitch-tui 0 - 2.4.1crates.io
xithrius/twitch-tui < 2.4.0
Published Aug 04, 2023
Tracked Since Feb 18, 2026