CVE-2022-21689 Affecting onionshare package, versions <2.5-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-ONIONSHARE-2347996
  • published20 Jan 2022
  • disclosed18 Jan 2022

Introduced: 18 Jan 2022

CVE-2022-21689  (opens in a new tab)

How to fix?

Upgrade Debian:unstable onionshare to version 2.5-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream onionshare package and not the onionshare package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions the receive mode limits concurrent uploads to 100 per second and blocks other uploads in the same second, which can be triggered by a simple script. An adversary with access to the receive mode can block file upload for others. There is no way to block this attack in public mode due to the anonymity properties of the tor network.

CVSS Scores

version 3.1