CVE-2022-29776: Critical severity onlyoffice document server vulnerability
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29776?
CVE-2022-29776 has a high severity rating due to the potential for remote code execution resulting from a stack overflow.
How do I fix CVE-2022-29776?
To mitigate CVE-2022-29776, upgrade ONLYOFFICE Document Server to version 6.1.0.27 or higher, and ONLYOFFICE Core to version 6.1.0.27 or higher.
What versions are affected by CVE-2022-29776?
CVE-2022-29776 affects ONLYOFFICE Document Server versions up to and including 6.0.0 and ONLYOFFICE Core versions up to and including 6.1.0.26.
What is the cause of CVE-2022-29776?
CVE-2022-29776 is caused by a stack overflow vulnerability found in the DesktopEditor component of the ONLYOFFICE software.
Is user interaction required for CVE-2022-29776 to be exploited?
CVE-2022-29776 does not require user interaction for exploitation, making it particularly dangerous.