CVE-2024-23692 — Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CVE-2024-23692: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Rejetto |
| Product | HTTP File Server |
| Date added | 2024-07-09 |
| Due date | 2024-07-30 |
| Ransomware campaign use | Known |
Description
Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.
Required action (CISA)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
The patched Rejetto HTTP File Server (HFS) is version 3: https://github.com/rejetto/hfs?tab=readme-ov-file#installation, https://www.rejetto.com/hfs/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-23692
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-23692
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog