CVE-2022-21695

MEDIUM

OnionShare < 2.5 - Unauthenticated Message Spoofing in Chat

Title source: llm
STIX 2.1

Description

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of chat participants. This issue has been resolved in version 2.5.

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/onionshare/onionshare/releases/tag/v2.5

Scores

CVSS v3 4.3
EPSS 0.0085
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
onionshare/onionshare < 2.5
pypi/onionshare-cli 2.3 - 2.5PyPI
Published Jan 18, 2022
Tracked Since Feb 18, 2026