Back to Database
Status published
Medium
CVE-2022-21692
Improper Access Control in Onionshare
Vulnerability Description
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-21692
Credits & Attribution
No credits recorded in the NVD database.
References
More from onionshare
View All →CVE-2022-21696
Username spoofing in OnionShare
Medium
4.3
CVE-2022-21695
Improper Access Control in Onionshare
Medium
4.3
CVE-2022-21694
OTF-006: Broken Website Hardening Control: The CSP can be turned on or off but not configured for the specific needs of the website
Low
3.7
CVE-2022-21693
Path traversal in Onionshare
Medium
6.3
CVE-2022-21691
Improper Access Control in Onionshare
Medium
4.3
Affected Vendor
onionshare
View all reports →Affected Software
onionshare
Vulnerable Versions:
< 2.5
Timeline
Official Publish:
January 18th, 2022
Last Modified:
April 22nd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N