CRITICAL

CVE-2024-23692

Rejetto Http File Server 2024-05-31 CVSS v3.1
CVSS
9.8
KEV

Description

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

Summary dbcve.org

Rejetto HTTP File Server versions up to and including 2.3m contain a template injection vulnerability that allows remote, unauthenticated attackers to execute arbitrary commands on the affected system via specially crafted HTTP requests. This is a critical RCE vulnerability with a CVSS score of 9.8.

Mitigation

Upgrade to a supported version of Rejetto HFS if available; if no patched version exists, migrate to an actively maintained alternative file server or implement compensating controls such as network segmentation and WAF rules to block malicious template syntax.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-1336
CWE-94 Code Injection

EPSS Score

99.47%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE