CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability
Summary
A path traversal vulnerability has been identified in ONLYOFFICE Docs, specifically when JSON Web Tokens (JWT) are utilized. This vulnerability, located in an image upload parameter, could potentially allow for remote code execution.
IFF Assessment
The identified path traversal vulnerability could allow remote code execution, posing a significant threat to systems and data.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: October 11, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability highlights the importance of securing file upload functionalities and validating user inputs, especially in applications that handle sensitive documents. Defenders should prioritize patching or mitigating this vulnerability promptly and review their incident response plans for handling potential remote code execution scenarios.