CVE | CVE-2021-43444 |
CVE Ordinal Value | 220505 |
Published Date | 2023-01-23T15:15Z |
Modified Date | 2023-01-23T17:17Z |
Description | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://github.com/ONLYOFFICE/server |
Reference Description | MISC https://github.com/ONLYOFFICE/server |
Reference URL | https://www.onlyoffice.com/ |
Reference Description | MISC https://www.onlyoffice.com/ |
Reference URL | https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Reference Description | MISC https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Sources | NIST MITRE |
Note
- No CVSS data for this CVE