CVE-2022-21695
Summary
| CVE | CVE-2022-21695 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-18 22:15:00 UTC |
| Updated | 2022-01-24 20:55:00 UTC |
| Description | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of chat participants. This issue has been resolved in version 2.5. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release OnionShare 2.5 · onionshare/onionshare · GitHub |
MISC |
github.com |
|
| OTF-009: Improper Access Control: Authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of chat participants · Advisory · onionshare/onionshare · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184956 Debian Security Update for onionshare (CVE-2022-21695)