CVE-2021-3199: Path Traversal
Published Jan 22, 2021
·Updated
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
Affected Software
1 affected component
Onlyoffice Document Server<5.6.3
Event History
Jan 22, 2021
CVE Published
via MITRE·02:41 AM
Data Sourced
via MITRE·02:41 AM
Description
Jan 26, 2021
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-3199?
CVE-2021-3199 is categorized as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2021-3199?
To fix CVE-2021-3199, upgrade ONLYOFFICE Document Server to version 5.6.3 or later.
3
What type of attack does CVE-2021-3199 involve?
CVE-2021-3199 involves a directory traversal attack allowing remote code execution.
4
Which component of ONLYOFFICE is affected by CVE-2021-3199?
CVE-2021-3199 affects the upload functionality in ONLYOFFICE Document Server.
5
Is CVE-2021-3199 exploitable without authentication?
Yes, CVE-2021-3199 can be exploited by unauthenticated users due to improper input validation.