CVE-2021-3199
Overview
This vulnerability is a directory traversal flaw rooted in insufficient validation of file path inputs during image uploads. The affected component is the /upload endpoint in ONLYOFFICE Document Server versions prior to 5.6.3 when JSON Web Tokens (JWT) are used for authentication. The flaw allows traversal sequences (e.g., /..) to manipulate file paths, enabling unauthorized access to the file system and execution of arbitrary code on the server.
Vulnerability Description
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
Impact
An unauthenticated attacker can exploit this vulnerability to upload malicious files outside the intended directory, resulting in remote code execution on the server hosting ONLYOFFICE Document Server. This enables full system compromise, including unauthorized access to sensitive data and potential lateral movement within the network. The attack requires no user interaction or valid credentials, increasing the risk of automated exploitation and widespread impact on affected deployments.
Solution
Upgrade ONLYOFFICE Document Server to version 5.6.3 or later, where the directory traversal vulnerability in the /upload endpoint has been addressed as documented in the official changelog (https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563). No specific workarounds are provided; applying the vendor patch is required to remediate the issue effectively.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Onlyoffice | Document Server | All |
cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Active exploitation confirmed with 293 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-3199 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/nola-milkin/poc_exploits/blob/master/CVE-2021-3199/poc_uploadImageFile.py |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/moehw/poc_exploits/tree/master/CVE-2021-3199/poc_uploadImageFile.py |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3199 |