GHSA-68vr-8f46-vc9f

    Dashboard / Vulnerabilities / GHSA-68vr-8f46-vc9f

    GHSA-68vr-8f46-vc9f

    Published: 21 Jan 2022Last Modified: 8 Oct 2024

    Summary: Username spoofing in OnionShare

    Details: Between September 26, 2021 and October 8, 2021, [Radically Open Security](https://www.radicallyopensecurity.com/) conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund's [Red Team lab](https://www.opentech.fund/labs/red-team-lab/). This is an issue from that penetration test. - Vulnerability ID: OTF-005 - Vulnerability type: Improper Input Sanitization - Threat level: Low ## Description: It is possible to change the username to that of another chat participant with an additional space character at the end of the name string. ## Technical description: Assumed users in Chat: - Alice - Bob - Mallory 1. Mallory renames to `Alice `. 2. Mallory sends message as `Alice `. 3. Alice and Bob receive a message from Mallory disguised as `Alice `, which is hard to distinguish from the `Alice` in the web interface. ![otf-005-a](https://user-images.githubusercontent.com/156128/140666112-8febd4d8-6761-41aa-955c-48be76f3c657.png) ![otf-005-b](https://user-images.githubusercontent.com/156128/140666113-1713ddf7-cef6-4dac-b718-9af1dc4ffdcd.png) Other (invisible) whitespace characters were found to be working as well. ## Impact: An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username. ## Recommendation: - Remove non-visible characters from the username

    Affected packages

    Package

    Name: onionshare-cli

    Purl: pkg:pypi/onionshare-cli

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.3
    Fixed -2.5

    Affected versions

    2.3
    2.3.1
    2.3.2
    2.3.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-68vr-8f46-vc9f | CVE-DB