CVE-2021-43445: Critical severity onlyoffice document server vulnerability
Published Jan 23, 2023
·Updated
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.
Affected Software
1 affected component
ONLYOFFICE Server<=7.0.0.49
Event History
Jan 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-43445?
The severity of CVE-2021-43445 is critical with a score of 9.8.
2
How does CVE-2021-43445 affect ONLYOFFICE?
CVE-2021-43445 affects all versions of ONLYOFFICE as of 2021-11-08.
3
What is the vulnerability in CVE-2021-43445?
The vulnerability in CVE-2021-43445 is Incorrect Access Control.
4
How can an attacker exploit CVE-2021-43445?
An attacker can authenticate with the web socket service of the ONLYOFFICE document editor using a default JWT signing key.
5
Is there a fix available for CVE-2021-43445?
Yes, updating ONLYOFFICE to a version higher than 7.0.0.49 will fix the issue.