GHSA-6rvj-pw9w-jcvc

Suggest an improvement
Source
https://github.com/advisories/GHSA-6rvj-pw9w-jcvc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-6rvj-pw9w-jcvc/GHSA-6rvj-pw9w-jcvc.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6rvj-pw9w-jcvc
Aliases
Published
2021-11-19T20:39:35Z
Modified
2026-07-06T08:11:51Z
Summary
Information disclosure vulnerability in OnionShare
Details

An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.

Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-10-05T15:16:30Z",
    "nvd_published_at":  "2021-10-04T14:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / onionshare-cli

Package

Name
onionshare-cli
View open source insights on deps.dev
Purl
pkg:pypi/onionshare-cli

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3
Fixed
2.4

Affected versions

2.*
2.3
2.3.1
2.3.2
2.3.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-6rvj-pw9w-jcvc/GHSA-6rvj-pw9w-jcvc.json"