CVE-2021-25829: High severity onlyoffice vulnerability
An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25829?
CVE-2021-25829 has a medium severity rating due to its potential for denial of service attacks.
How do I fix CVE-2021-25829?
To address CVE-2021-25829, users should upgrade ONLYOFFICE DocumentServer to a version later than 5.6.3.
What type of vulnerability is CVE-2021-25829?
CVE-2021-25829 is a denial of service vulnerability caused by improper binary stream data handling.
Which versions of ONLYOFFICE DocumentServer are affected by CVE-2021-25829?
Versions from 4.0.0-9 to 5.6.3 of ONLYOFFICE DocumentServer are vulnerable to CVE-2021-25829.
What can an attacker achieve by exploiting CVE-2021-25829?
An attacker exploiting CVE-2021-25829 can create conditions that may lead to a denial of service and shutdown the target server.