CVE-2017-8822 describes a vulnerability in Tor, affecting versions prior to 0.2.5.16, 0.2.8.17, 0.2.9.14, 0.3.0.13, and 0.3.1.9, where relays with incomplete descriptor downloads could select themselves in a circuit path. This issue, also known as TROVE-2017-012, primarily impacts user anonymity. The vulnerability has a low CVSS score of 3.7, indicating a network-based attack with high complexity and no user interaction required. The potential impact is limited to a degradation of anonymity (low confidentiality), with no integrity or availability concerns. There is no evidence of active exploitation, nor are there any public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.5.16CPE matchmatch criteria | cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:* | ||
>= 0.2.6, < 0.2.8.17CPE matchmatch criteria | cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:* | ||
>= 0.2.9, < 0.2.9.14CPE matchmatch criteria | cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:* | ||
>= 0.3.0, < 0.3.0.13CPE matchmatch criteria | cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:* | ||
>= 0.3.1, < 0.3.1.9CPE matchmatch criteria | cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.