← Back to browse · API

CVE-2021-43445

Severity
CRITICAL
CVSS
9.8
EPSS
0.01707
Risk score
39.8
CISA KEV
No
PoC
No
Published
2023-01-23
Modified
2025-04-02
First seen
2026-08-07
Aliases
EUVD-2021-30378, GHSA-7WJ3-GW7R-QR35
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-30378

Description

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.

References