Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-21694

Опубликовано: 18 янв. 2022
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 3.7

Описание

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

2.6.3-1
esm-apps/bionic

not-affected

0.9.2-1
esm-apps/focal

ignored

changes too intrusive
esm-apps/jammy

ignored

changes too intrusive
esm-apps/noble

not-affected

2.6-6ubuntu1
esm-apps/xenial

not-affected

0.8.1-1
focal

ignored

end of standard support, was needs-triage
impish

ignored

end of life
jammy

ignored

changes too intrusive

Показывать по

5 Medium

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
около 4 лет назад

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.

CVSS3: 3.7
debian
около 4 лет назад

OnionShare is an open source tool that lets you securely and anonymous ...

CVSS3: 3.7
github
около 4 лет назад

Incorrect Permission Assignment for Critical Resource in OnionShare

5 Medium

CVSS2

3.7 Low

CVSS3