Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwjq-6wrh-5w8q

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

Withdrawn Advisory: OnionShare Predictable Pathname

Withdrawn Advisory

This advisory has been withdrawn because the advisory concerns the repository https://github.com/onionshare/onionshare, which is not in a supported ecosystem. onionshare-cli is not affected by this issue.

Original Description

The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.

Пакеты

Наименование

onionshare-cli

pip
Затронутые версииВерсия исправления

<= 1.3.1

Отсутствует

EPSS

Процентиль: 6%
0.00024
Низкий

7 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7
ubuntu
около 7 лет назад

The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.

CVSS3: 7
nvd
около 7 лет назад

The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.

CVSS3: 7
debian
около 7 лет назад

The debug_mode function in web/web.py in OnionShare through 1.3.1, whe ...

EPSS

Процентиль: 6%
0.00024
Низкий

7 High

CVSS3

Дефекты

CWE-20