Skip to content

Information disclosure vulnerability in OnionShare

Moderate severity GitHub Reviewed Published Nov 19, 2021 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

pip onionshare-cli (pip)

Affected versions

>= 2.3, < 2.4

Patched versions

2.4

Description

An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.

References

Published by the National Vulnerability Database Oct 4, 2021
Reviewed Oct 5, 2021
Published to the GitHub Advisory Database Nov 19, 2021
Last updated Feb 1, 2023

Severity

Moderate

EPSS score

0.241%
(65th percentile)

Weaknesses

CVE ID

CVE-2021-41867

GHSA ID

GHSA-6rvj-pw9w-jcvc

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.