A vulnerability was identified in ONLYOFFICE Docs. A remote attacker could exploit this vulnerability to trigger remote code execution and security restriction bypass on the targeted system.
CVE-2021-3199 is being exploited in the wild. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Hence, the risk level is rated as High Risk.
Security Restriction Bypass
System / Technologies affected
ONLYOFFICE Document Server versions earlier than 5.6.3
ONLYOFFICE Document Server to version 5.6.3 or later
Vulnerability Identifier
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
