CVE-2022-21692
Summary
| CVE | CVE-2022-21692 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-18 23:15:00 UTC |
| Updated | 2022-01-24 21:05:00 UTC |
| Description | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release OnionShare 2.5 · onionshare/onionshare · GitHub |
MISC |
github.com |
|
| OTF-003: Improper Access Control: Anyone with access to the chat environment can write messages disguised as another chat participant · Advisory · onionshare/onionshare · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182560 Debian Security Update for onionshare (CVE-2022-21692)