CVE-2023-30187: Critical severity Onlyoffice Document Server vulnerability
Published Aug 14, 2023
·Updated
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Affected Software
1 affected component
Onlyoffice Document Server>=4.0.3<=7.3.2
Remediation
Event History
Aug 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-30187?
CVE-2023-30187 is classified as a critical severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2023-30187?
To mitigate CVE-2023-30187, upgrade ONLYOFFICE DocumentServer to version 7.3.3 or later.
3
What software is affected by CVE-2023-30187?
CVE-2023-30187 affects ONLYOFFICE DocumentServer versions from 4.0.3 to 7.3.2.
4
What type of vulnerability is CVE-2023-30187?
CVE-2023-30187 is an out of bounds memory access vulnerability.
5
Can CVE-2023-30187 allow remote attacks?
Yes, CVE-2023-30187 allows remote attackers to run arbitrary code via a crafted JavaScript file.