CISA KEV Adds ONLYOFFICE Docs Server Path Traversal Flaw (CVE-2021-3199)
What Happened
CISA has added CVE-2021-3199, a path traversal vulnerability in ONLYOFFICE Docs Server, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild. According to the vendor's changelog, the flaw occurs when JWT authentication is enabled and involves a /.. sequence passed through an image upload parameter, potentially allowing remote code execution.
Why It Matters
ONLYOFFICE Docs is widely deployed for self-hosted document collaboration, often integrated with platforms like Nextcloud, ownCloud, and various CRMs. A path traversal bug reachable via an unauthenticated or lightly authenticated upload parameter — with a potential path to RCE — is a serious concern for any organization running an exposed or internet-facing Docs Server instance, particularly given its KEV status signals real-world attacker interest rather than theoretical risk.
What Defenders Should Do Now
- Inventory any ONLYOFFICE Docs Server instances, especially those with JWT enabled and reachable from the internet.
- Confirm patch status against the vendor's changelog and update to a fixed version as a priority.
- Hunt for anomalous image upload requests containing directory traversal sequences (e.g.,
/..) in web server and application logs. - Review file system write locations for unexpected files created outside expected upload directories, which could indicate successful traversal.
- Monitor for unusual process spawning from the Docs Server host, consistent with a traversal-to-RCE chain.
- If an exposed instance cannot be patched immediately, restrict network access or disable JWT-dependent upload paths as a temporary mitigation.
Developing Intel
This is a same-day KEV addition and details may evolve as CISA, the vendor, and the community publish further analysis. This post reflects currently available information; no specific exploitation campaign or threat actor has been attributed in the source material. See the vendor's changelog for authoritative details: ONLYOFFICE DocumentServer CHANGELOG #563.