Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68vr-8f46-vc9f

Опубликовано: 21 янв. 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Username spoofing in OnionShare

Between September 26, 2021 and October 8, 2021, Radically Open Security conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund's Red Team lab. This is an issue from that penetration test.

  • Vulnerability ID: OTF-005
  • Vulnerability type: Improper Input Sanitization
  • Threat level: Low

Description:

It is possible to change the username to that of another chat participant with an additional space character at the end of the name string.

Technical description:

Assumed users in Chat:

  • Alice
  • Bob
  • Mallory
  1. Mallory renames to Alice .
  2. Mallory sends message as Alice .
  3. Alice and Bob receive a message from Mallory disguised as Alice , which is hard to distinguish from the Alice in the web interface.

otf-005-a otf-005-b

Other (invisible) whitespace characters were found to be working as well.

Impact:

An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.

Recommendation:

  • Remove non-visible characters from the username

Пакеты

Наименование

onionshare-cli

pip
Затронутые версииВерсия исправления

>= 2.3, < 2.5

2.5

EPSS

Процентиль: 43%
0.00209
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 4 лет назад

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.

CVSS3: 4.3
nvd
около 4 лет назад

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.

CVSS3: 4.3
debian
около 4 лет назад

OnionShare is an open source tool that lets you securely and anonymous ...

EPSS

Процентиль: 43%
0.00209
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-20