CVE-2022-21696
- EPSS 0.71%
- Veröffentlicht 18.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:45:15
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an a...
CVE-2021-41867
- EPSS 1.79%
- Veröffentlicht 04.10.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:55
An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.
CVE-2021-41868
- EPSS 2.4%
- Veröffentlicht 04.10.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:55
OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.
- EPSS 0.34%
- Veröffentlicht 07.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:53
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathn...
CVE-2016-5026
- EPSS 0.32%
- Veröffentlicht 30.01.2017 22:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.