CVE-2021-43444
Published on: Not Yet Published
Last Modified on: 01/23/2023 05:17:00 PM UTC
The following vulnerability was found:
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
- CVE-2021-43444 has been assigned by
[email protected] to track the vulnerability
CVE References
Description | Tags ⓘ | Link |
---|---|---|
ONLYOFFICE - Online Office for business | ONLYOFFICE | www.onlyoffice.com application/x-wine-extension-ini |
![]() |
Remote Code Execution in ONLYOFFICE - Nettitude Labs | labs.nettitude.com text/html |
![]() |
GitHub - ONLYOFFICE/server: The backend server software layer which is the part of ONLYOFFICE Document Server and is the base for all other components | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
There are no known software configurations (CPEs) currently associated with this CVE
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-43444 - 43449 Exploiting ONLYOFFICE Web Sockets for Unauth #RCE labs.nettitude.com/blog/exploitin… | 2022-12-16 12:15:03 |
![]() |
CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution labs.nettitude.com/blog/exploitin… | 2022-12-19 08:01:24 |
![]() |
The vuln CVE-2021-43444 has a tweet created 1 days ago and retweeted 10 times. twitter.com/tbbhunter/stat… #pow1rtrtwwcve | 2022-12-20 12:06:01 |
![]() |
CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution… twitter.com/i/web/status/1… | 2022-12-21 06:25:10 |
![]() |
CVE-2021-43444 到 43449:利用 ONLYOFFICE Web 套接字进行未经身份验证的远程代码执行 ift.tt/6qk2yBL ift.tt/2FNWznv | 2022-12-22 01:16:11 |
![]() |
CVE-2021-43444 到 43449:利用 ONLYOFFICE Web 套接字进行未经身份验证的远程代码执行 ift.tt/1KDeaJZ ift.tt/DgO2FhS | 2022-12-23 02:16:13 |
![]() |
CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution… twitter.com/i/web/status/1… | 2023-01-02 09:08:14 |
![]() |
CVE-2021-43444 to 43449: Unauthenticated Remote Code Execution Exploitation of ONLYOFFICE Web Sockets xz.aliyun.com/t/12008 | 2023-01-05 19:53:40 |
![]() |
CVE-2021-43444 到 43449:利用 ONLYOFFICE Web 套接字进行未经身份验证的远程代码执行 ift.tt/OYRew6A ift.tt/VsyD48H | 2023-01-07 22:38:36 |
![]() |
CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution #bugbounty… twitter.com/i/web/status/1… | 2023-01-21 09:00:17 |
![]() |
CVE-2021-43444 : ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document… twitter.com/i/web/status/1… | 2023-01-23 15:23:53 |
![]() |
CVE-2021-43444 | 2023-01-23 16:40:14 |