Information Disclosure Vulnerability in OnionShare by OnionShare
CVE-2021-41867

5.3MEDIUM

Key Information:

Vendor

Onionshare

Vendor
CVE Published:
4 October 2021

What is CVE-2021-41867?

An information disclosure vulnerability in OnionShare prior to version 2.4 permits remote attackers to gain unauthorized access to the complete list of participants in a non-public OnionShare node. This is achieved through the --chat feature, which exposes sensitive participant information to unauthenticated users, creating significant privacy concerns for OnionShare users.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.