PT-2022-11839 · Unknown · Onlyoffice

Iain Wallace

·

Published

2022-12-16

·

Updated

2026-05-01

·

CVE-2021-43444

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ONLYOFFICE versions prior to 2021-11-08
Description Incorrect access control allows signed document download URLs to be forged because of a weak default URL signing key. Additionally, an unauthenticated WebSocket allows for document downloads, macro injection, and Server-Side Request Forgery (SSRF), which is a technique where an attacker forces a server to make requests to an unintended location. This is facilitated by a default JSON Web Token (JWT) key set to secret.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-43444

Affected Products

Onlyoffice