Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Dromara Skyeye, a platform that includes document management and collaboration features. The issue allows unauthenticated attackers to potentially access internal server resources and overwrite user files, which could have significant implications for data integrity and confidentiality. The main concern is confirming relevance and exposure given the nature of the affected functionality.
- Attackers can access internal files and overwrite user data.
- This vulnerability impacts document management and collaboration systems.
- Confirm relevance and exposure for affected systems.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by sending a crafted request to the vulnerable component, potentially leading to unauthorized access and modification of files. The attacker initiates the attack by targeting the editUploadOfficeFileById function, which is exposed through the application's interface. By manipulating specific parameters within this function, the attacker can trick the server into fetching external or internal resources and overwriting existing files. The results of this action can then be retrieved using another function.
- No authentication required.
- Triggered by an upload callback request.
- Overwrite files and read results.
Live Threat
Current exploitation, exposure, and threat context
A server-side request forgery vulnerability in Dromara Skyeye, when supported by the advisory's conditions, could allow unauthenticated attackers to make the server fetch internal URLs. This could lead to the overwriting of any user's stored file and subsequent reading of its contents.
- User-stored files could be overwritten.
- Arbitrary URLs can be fetched by the server.
- Sensitive user files may be exposed.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability impacts Dromara Skyeye, specifically its OnlyOffice integration for file handling. Owners of application platforms integrating this functionality or infrastructure teams managing the deployed instances must prioritize identifying all instances, assessing their exposure and business criticality, and confirming the accountable parties. Remediation planning should proceed based on the identified risk.
- Application or platform owners should manage the issue.
- Verify Skyeye instance reachability and criticality first.
- Plan remediation based on risk and vendor coordination.