Horizon Alert
Summary of the vulnerability and why it matters
A directory traversal vulnerability in ONLYOFFICE Document Server could allow an unauthenticated attacker to execute arbitrary code on the server. This is due to a flaw in the image upload functionality when JSON Web Token (JWT) is enabled, which could be exploited by manipulating an image upload parameter to traverse directories. The main concern is confirming relevance and exposure given the potential for critical impact.
- Allows code execution via file uploads.
- Critical vulnerability, remotely exploitable without authentication.
- Confirm system relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending specially crafted requests to the image upload feature. This feature, located at `/upload`, is exposed externally and does not require authentication. By manipulating an image upload parameter with a directory traversal sequence, an attacker can trick the server into writing files to arbitrary locations, potentially leading to remote code execution.
- Accessible over the network.
- Directory traversal via image upload parameter.
- Remote code execution.
Live Threat
Current exploitation, exposure, and threat context
Directory traversal with remote code execution could affect the integrity and availability of the ONLYOFFICE Document Server when JWT is enabled and an attacker can control image upload parameters. This could lead to unauthorized code execution on the server.
- Server code execution.
- Malicious file upload.
- Unauthorized server control.
Operational Fix
Recommended remediation, mitigation, and detection steps
Attackers can exploit this critical vulnerability remotely through a directory traversal flaw in the image upload functionality of ONLYOFFICE Document Server when JWT is enabled. Technical leaders should direct their security and infrastructure teams to identify all instances of ONLYOFFICE Document Server, assess their network exposure and business criticality, and confirm ownership. Subsequently, a risk-based remediation plan, potentially involving vendor coordination or temporary controls, should be developed and executed.
- Document Server owners should lead remediation efforts.
- Verify internet-facing and critical deployments first.
- Plan vendor-coordinated updates or risk reduction.