PT-2022-15043 · Unknown · Onionshare

Micahflee

·

Published

2022-01-18

·

Updated

2024-06-15

·

CVE-2022-21691

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OnionShare versions prior to 2.5
Description The issue allows chat participants to spoof their channel leave message, tricking others into assuming they left the chatroom. This can be exploited by an adversary with access to the chat environment, enabling them to persist in the chat with access to all sent messages and the possibility to write in the chat. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations Implement proper session handling to prevent chat participants from spoofing their channel leave message. As a temporary workaround, consider monitoring chatroom activity closely to detect potential spoofing attempts until a patch is available. Restrict access to the chat environment to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21691
GHSA-W9M4-7W72-R766
OPENSUSE-SU-2024:11983-1
OPENSUSE-SU-2024:13635-1
PYSEC-2022-42

Affected Products

Onionshare