CVE-2021-3199 Elastic Security · Elastic

Detect ONLYOFFICE Docs Server Path Traversal (CVE-2021-3199) in Elastic Security

Detects exploitation of a path traversal vulnerability (CWE-22) in ONLYOFFICE Docs (Document Server). An attacker can supply crafted directory-traversal sequences (e.g. ../, encoded ..%2f, ..%5c) in document conversion or download requests handled by the DocumentServer web services, allowing read/write access to files outside the intended document storage directory. Listed in the CISA KEV catalog. This detection surfaces HTTP requests to ONLYOFFICE Docs endpoints containing traversal sequences and anomalous local file access by the DocumentServer service account.

MITRE ATT&CK

Tactic
Initial Access Collection

Elastic Detection Query

Elastic Security (Elastic)
eql
network where event.category == "web" and
  (url.path like~ "*ConvertService*" or url.path like~ "*downloadas*" or url.path like~ "*FileUploader*" or url.path like~ "*/cache/files*" or url.path like~ "*/coauthoring*") and
  (url.path : ("*../*", "*..\\*", "*%2e%2e%2f*", "*..%2f*", "*..%5c*") or
   url.query : ("*../*", "*..\\*", "*%2e%2e%2f*", "*..%2f*", "*..%5c*", "*%252e%252e*"))
high severity high confidence

EQL rule matching HTTP events to ONLYOFFICE Docs endpoints containing directory traversal sequences in the URL path or query, including encoded variants.

Data Sources

Elastic web/HTTP ingest (Filebeat nginx/iis modules)Packetbeat HTTP

Required Tables

logs-nginx.access-*logs-iis.access-*packetbeat-*

False Positives & Tuning

  • Legitimate conversion callbacks embedding relative paths in parameters.
  • Authorized scanning activity.
  • Synthetic monitoring traffic.

Other platforms for CVE-2021-3199


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Basic path traversal against ConvertService

    Expected signal: Web/IIS access log entry for /ConvertService with '../' sequences in the query string from the test source IP.

  2. Test 2URL-encoded traversal against downloadas endpoint

    Expected signal: Access log entry containing %2e%2e%2f encoded sequences on the downloadas endpoint.

  3. Test 3Double-encoded traversal on Windows host

    Expected signal: IIS W3C log entry with %252e%252e double-encoded sequences on the FileUploader endpoint.


Response Playbook

Triage

  1. Confirm the target host runs ONLYOFFICE Docs/DocumentServer and identify the exposed version against the fixed release in the vendor CHANGELOG to determine whether it is vulnerable.
  2. Decode the full request URI (handle single and double URL-encoding) and determine the file path the traversal sequence resolves to relative to the DocumentServer document root.
  3. Check the HTTP response status and size for the flagged requests — a 200 with a non-trivial body indicates successful file disclosure, while 400/404 suggests a blocked or failed attempt.
  4. Correlate the source IP against known scanners, VPN ranges, and prior authentication events to judge whether this is reconnaissance or targeted exploitation.

Containment

  1. Block the offending source IP(s) at the WAF/reverse proxy and apply a rule rejecting URIs containing `..`, `%2e%2e`, and encoded path separators on ONLYOFFICE endpoints.
  2. Isolate or restrict external access to the ONLYOFFICE Docs server (place behind VPN/allowlist) until the fixed version is deployed.
  3. Rotate any credentials, JWT signing secrets, or configuration files that reside within the reachable directory tree if file disclosure is confirmed.

Evidence Collection

  1. Preserve IIS/nginx/proxy access logs and DocumentServer application logs covering the attack window, including full raw URIs.
  2. Capture the DocumentServer process file-access audit trail (auditd on Linux / Sysmon FileCreate+FileRead on Windows) for files touched by the service account around the request time.

Escalation Criteria

  • !Escalate to IR if a flagged request returned a 200 with response content indicating sensitive files (config, JWT secret, /etc/passwd) were disclosed.
  • !Escalate if post-exploitation file writes, new scheduled tasks/cron, or unexpected child processes of the DocumentServer service are observed following the traversal attempts.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >IIS/nginx/reverse-proxy access logs containing traversal URIs on ONLYOFFICE endpoints.
  • >DocumentServer application and conversion-service logs.
  • >OS-level file access audit records (auditd/Sysmon) for the DocumentServer service account.

Tuning Guidance

Baseline legitimate ONLYOFFICE conversion callbacks, which may include relative path fragments in the document url/key parameters, and exclude the known DocumentServer callback IPs/service accounts. If false positives persist from conversion traffic, require the decoded path to resolve above the document root (presence of `../` sequences that escape the base directory) and prioritize requests that returned HTTP 200 with a body size inconsistent with normal API responses.


Hunting Queries

Aggregates ONLYOFFICE Docs requests containing decoded traversal sequences by source IP to surface scanning or exploitation bursts.

Hunting — KQL
kql
W3CIISLog | where csUriStem has_any (dynamic(["ConvertService","downloadas","FileUploader","coauthoring"])) | extend d=url_decode(strcat(csUriStem, csUriQuery)) | where d has ".." | summarize count(), make_set(d) by cIP, bin(TimeGenerated, 1h) | order by count_ desc
Hunting — SPL
spl
index=web (uri_path="*ConvertService*" OR uri_path="*downloadas*" OR uri_path="*FileUploader*") | eval d=urldecode(uri_path.uri_query) | where match(d,"\.\.[\/\\]") | stats count values(d) by src_ip

Atomic Red Team Tests

Test 1 Basic path traversal against ConvertService
linux

Sends an HTTP request to the ONLYOFFICE Docs conversion endpoint with a directory traversal sequence in the file url parameter to attempt reading a file outside the document root.

Command

bash
curl -s -o /tmp/cve_2021_3199_resp.txt -w '%{http_code}\n' "http://onlyoffice.lab.local/ConvertService.ashx?url=../../../../../../etc/passwd"

Cleanup

bash
rm -f /tmp/cve_2021_3199_resp.txt

Expected Telemetry

Web/IIS access log entry for /ConvertService with '../' sequences in the query string from the test source IP.

Expected Detection

KQL/SPL rules match the traversal sequence against the ConvertService endpoint.

Test 2 URL-encoded traversal against downloadas endpoint
linux

Attempts traversal using single URL-encoding (%2e%2e%2f) against the download endpoint to evade naive string matching.

Command

bash
curl -s -o /dev/null -w '%{http_code}\n' "http://onlyoffice.lab.local/downloadas?filename=%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd"

Cleanup

bash
echo 'no cleanup required'

Expected Telemetry

Access log entry containing %2e%2e%2f encoded sequences on the downloadas endpoint.

Expected Detection

Detection decodes the URI and matches the encoded traversal pattern.

Test 3 Double-encoded traversal on Windows host
windows

Uses double URL-encoding (%252e%252e) in a PowerShell web request against the FileUploader endpoint to test decoding-based detection on a Windows ONLYOFFICE deployment.

Command

powershell
powershell -Command "try { Invoke-WebRequest -Uri 'http://onlyoffice.lab.local/FileUploader.ashx?name=%252e%252e%255c%252e%252e%255cweb.config' -UseBasicParsing } catch { $_.Exception.Response.StatusCode.value__ }"

Cleanup

powershell
powershell -Command "Remove-Item -Path $env:TEMP\cve_2021_3199* -ErrorAction SilentlyContinue"

Expected Telemetry

IIS W3C log entry with %252e%252e double-encoded sequences on the FileUploader endpoint.

Expected Detection

Detection matches double-encoded traversal via the %252e%252e pattern branch.

Related Detections