Skip to content
Brief Security & Trust ·

HKCERT: ONLYOFFICE Docs flaw CVE-2021-3199 is being exploited in the wild

The bug can let a remote attacker run code on servers using older ONLYOFFICE Document Server versions.

In brief
  • HKCERT says CVE-2021-3199 in ONLYOFFICE Docs is being exploited in the wild and rates it High Risk.
  • Document Server versions before 5.6.3 are affected. HKCERT advises updating to 5.6.3 or later.

HKCERT said on 9 October that attackers are exploiting a flaw in ONLYOFFICE Docs, tracked as CVE-2021-3199. It describes a path traversal bug, where a crafted file path reaches folders it should not. The bug appears when the product uses JWT, a signed token apps use to check access. An attacker can add a "/.." sequence to an image upload parameter. HKCERT says this could let a remote attacker run code on the system and bypass security limits. It rates the risk High. The affected software is ONLYOFFICE Document Server before version 5.6.3, and HKCERT advises moving to 5.6.3 or later.

The bulletin leaves several things open. It does not say who is carrying out the attacks, how many systems have been hit, or when the attacks began. It gives no detail on what attackers do after they get in. It lists no workaround other than updating. For its references, it points to the ONLYOFFICE changelog for version 5.6.3 and to the CISA known exploited vulnerabilities catalog.

Teams that run ONLYOFFICE Document Server should check which version they have. Any version older than 5.6.3 falls inside the range HKCERT names, and the flaw is reported as actively exploited.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: HKCERT, HKCERT, slcyber.io.