Withdrawn Advisory: OnionShare Predictable Pathname
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Oct 9, 2023
Withdrawn
This advisory was withdrawn on Oct 9, 2023
Description
Published by the National Vulnerability Database
Dec 7, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jul 24, 2023
Withdrawn
Oct 9, 2023
Last updated
Oct 9, 2023
Withdrawn Advisory
This advisory has been withdrawn because the advisory concerns the repository https://github.com/onionshare/onionshare, which is not in a supported ecosystem. onionshare-cli is not affected by this issue.
Original Description
The
debug_mode
function inweb/web.py
in OnionShare through 1.3.1, when--debug
is enabled, uses the/tmp/onionshare_server.log
pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.References