VDB
CVE-2022-21693
CVE-2022-21693
PUBLISHED
CVSS 6.300000190734863 MEDIUM
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions an adversary with a primitive that allows for filesystem access from the context of the Onionshare process can access sensitive files in the entire user home folder. This could lead to the leaking of sensitive data. Due to the automatic exclusion of hidden folders, the impact is reduced. This can be mitigated by usage of the flatpak release.
EPSS 1.13% · 63.3th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score
1.13%
63.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| onionshare | onionshare | 2.3, * |
| PyPI | onionshare-cli | 2.3 |
Timeline
- Jan 18, 2022 CVE Published
- Jan 19, 2022 PoC Published
- Feb 8, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 24, 2022 EPSS Score
- Jul 16, 2022 EPSS Score
- Sep 7, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- May 27, 2023 EPSS Score
References
- https://github.com/onionshare/onionshare/releases/tag/v2.5 url
- https://github.com/onionshare/onionshare/security/advisories/GHSA-jgm9-xpfj-4fq6 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-21693 advisory
- https://github.com/onionshare/onionshare package
- https://github.com/pypa/advisory-database/tree/main/vulns/onionshare-cli/PYSEC-2022-44.yaml url