Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21694

Опубликовано: 18 янв. 2022
Источник: nvd
CVSS3: 3.7
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:onionshare:onionshare:*:*:*:*:*:*:*:*
Версия до 2.5 (исключая)

EPSS

Процентиль: 49%
0.00255
Низкий

3.7 Low

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-732
CWE-732

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 4 лет назад

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.

CVSS3: 3.7
debian
около 4 лет назад

OnionShare is an open source tool that lets you securely and anonymous ...

CVSS3: 3.7
github
около 4 лет назад

Incorrect Permission Assignment for Critical Resource in OnionShare

EPSS

Процентиль: 49%
0.00255
Низкий

3.7 Low

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-732
CWE-732