CVE-2021-43449: SSRF
Published Jan 23, 2023
·Updated
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document.
Affected Software
1 affected component
ONLYOFFICE Server<=7.0.0.49
Event History
Jan 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-43449.
2
What is the severity of CVE-2021-43449?
The severity of CVE-2021-43449 is high with a CVSS score of 8.1.
3
What is the affected software for CVE-2021-43449?
The affected software for CVE-2021-43449 is ONLYOFFICE Server versions up to and including 7.0.0.49.
4
What is Server-Side Request Forgery (SSRF)?
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests to internal or external resources on behalf of the targeted server.
5
How can an attacker exploit CVE-2021-43449?
An attacker can exploit CVE-2021-43449 by abusing the document editor service in ONLYOFFICE to read and serve arbitrary URLs as a document.