VDB
CVE-2022-21692
CVE-2022-21692
PUBLISHED
CVSS 4.300000190734863 MEDIUM
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant.
EPSS 0.77% · 52.2th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.77%
52.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | onionshare-cli | 2.3 |
| onionshare | onionshare | < 2.5, 0 |
Timeline
- Jan 18, 2022 CVE Published
- Jan 19, 2022 PoC Published
- Feb 8, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 24, 2022 EPSS Score
- Jul 16, 2022 EPSS Score
- Sep 7, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
References
- https://github.com/onionshare/onionshare/releases/tag/v2.5 url
- https://github.com/onionshare/onionshare/security/advisories/GHSA-gjj5-998g-v36v url
- https://nvd.nist.gov/vuln/detail/CVE-2022-21692 advisory
- https://github.com/onionshare/onionshare package
- https://github.com/pypa/advisory-database/tree/main/vulns/onionshare-cli/PYSEC-2022-43.yaml url