Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution
What It Is – ONLYOFFICE Docs contains a server‑side path traversal flaw (CVE‑2021‑3199). An attacker can embed a “/..” sequence in the image‑upload parameter while a JWT token is being processed, causing the application to read or write files outside the intended directory and potentially execute arbitrary code.
Exploitability – Publicly disclosed; proof‑of‑concept code is available. The CVSS v3.1 base score is 9.8 (Critical), indicating a high likelihood of remote exploitation without authentication.
Affected Products – ONLYOFFICE Docs (on‑premises and SaaS deployments) that accept image uploads with JWT‑based authentication.
Why It Matters for Trust & Control Assurance
- Control Mapping – The flaw tests the “secure configuration and vulnerability remediation” control objective, a single control that maps to many frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).
- Continuous Monitoring – Demonstrates the need for ongoing third‑party component scanning and evidence collection to prove due diligence.
- Audit Readiness – Remediation evidence (patch deployment, configuration hardening) becomes a defensible artifact for auditors demanding a trusted supply‑chain posture.
Recommended Actions
- Apply the vendor‑released patch for CVE‑2021‑3199 immediately.
- Review and tighten JWT validation logic to reject “/..” sequences.
- Integrate ONLYOFFICE Docs into your automated vulnerability‑scanning pipeline.
- Document the remediation steps in your control‑evidence repository for audit purposes.
Source: CISA KEV – CVE‑2021‑3199