CVE-2021-41868 log

Source
Severity Medium
Remote Yes
Type Arbitrary file upload
Description
OnionShare before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.
Group Package Affected Fixed Severity Status Ticket
AVG-2436 onionshare 2.2-5 2.4-1 Medium Fixed
References
https://www.ihteam.net/advisory/onionshare/
https://github.com/onionshare/onionshare/issues/1396
https://github.com/onionshare/onionshare/pull/1404