PT-2022-15047 · Unknown · Onionshare
Micahflee
·
Published
2022-01-18
·
Updated
2024-06-15
·
CVE-2022-21695
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OnionShare versions prior to 2.5
Description
OnionShare is an open source tool that lets users securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions, authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of chat participants. This issue allows an adversary with access to the chat environment to send messages to the chat without being visible in the list of chat participants.
Recommendations
For OnionShare versions prior to 2.5:
Update to version 2.5 to resolve the issue.
As a temporary workaround, consider implementing proper session handling and allowing chat access only after emission of the join event.
Restrict access to the chat environment to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onionshare