CVE | CVE-2021-43445 |
CVE Ordinal Value | 220506 |
Published Date | 2023-01-23T15:15Z |
Modified Date | 2023-01-31T15:07Z |
CWE Type | CWE-287 |
CVSS 3.x | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Description | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://github.com/ONLYOFFICE/server |
Reference Description | MISC https://github.com/ONLYOFFICE/server |
Reference URL | https://www.onlyoffice.com/ |
Reference Description | MISC https://www.onlyoffice.com/ |
Reference URL | https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Reference Description | MISC https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/ |
Tags | Third Party Advisory |
Sources | NIST MITRE |