PT-2021-23437 · Unknown · Onionshare
Byr00T
·
Published
2021-10-04
·
Updated
2024-06-15
·
CVE-2021-41867
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OnionShare versions 2.3 through 2.3
Description
An information disclosure issue allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.
Recommendations
For OnionShare version 2.3, update to version 2.4 to resolve the issue.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onionshare