CVE-2021-43444: High severity onlyoffice document server vulnerability
Published Jan 23, 2023
·Updated
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
Affected Software
1 affected component
ONLYOFFICE Server<=7.0.0.49
Event History
Jan 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-43444?
The severity of CVE-2021-43444 is high with a CVSS score of 7.5.
2
How does CVE-2021-43444 impact ONLYOFFICE?
CVE-2021-43444 affects ALL versions of ONLYOFFICE as of 2021-11-08 by allowing forged download URLs for signed documents due to a weak default URL signing key.
3
Is CVE-2021-43444 related to Incorrect Access Control in ONLYOFFICE?
Yes, CVE-2021-43444 is related to Incorrect Access Control in ONLYOFFICE where signed document download URLs can be forged.
4
What is the CWE associated with CVE-2021-43444?
CVE-2021-43444 is associated with CWE-287.