GHSA-6rvj-pw9w-jcvc

Suggest an improvement
Source
https://github.com/advisories/GHSA-6rvj-pw9w-jcvc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-6rvj-pw9w-jcvc/GHSA-6rvj-pw9w-jcvc.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6rvj-pw9w-jcvc
Aliases
Published
2021-11-19T20:39:35Z
Modified
2024-12-02T05:47:20.754088Z
Summary
Information disclosure vulnerability in OnionShare
Details

An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.

Database specific
{
    "nvd_published_at": "2021-10-04T14:15:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2021-10-05T15:16:30Z"
}
References

Affected packages

PyPI / onionshare-cli

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3
Fixed
2.4

Affected versions

2.*

2.3
2.3.1
2.3.2
2.3.3