CVE-2022-21691

MEDIUM

OnionShare < 2.5 - Unauthenticated Channel Leave Message Spoofing

Title source: llm
STIX 2.1

Description

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions chat participants can spoof their channel leave message, tricking others into assuming they left the chatroom.

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/onionshare/onionshare/releases/tag/v2.5

Scores

CVSS v3 4.3
EPSS 0.0067
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
onionshare/onionshare < 2.5
pypi/onionshare-cli 2.3 - 2.5PyPI
Published Jan 18, 2022
Tracked Since Feb 18, 2026