Releases29
Frequency2 months 5 days
Last Release
NodeJS Transifex API Client

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 0.5, = 0.3, = 0.1, = 0.2, = 0.6, <= 0.8, = 0.4, = 0.74.3 MEDIUM

Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate.

= 0.5, = 0.3, = 0.1, = 0.8, = 0.2, = 0.6, <= 0.9, = 0.4, = 0.74.3 MEDIUM

Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2073.