CVE-2024-23692: critical vulnerability in Rejetto HTTP File Server
Rejetto HTTP File Server 2.3m Unauthenticated RCE
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Rejetto HTTP File Server version 2.3m and earlier has a critical flaw that allows anyone on the internet to run malicious commands on the affected computer by sending a specially crafted request. No login is required, making it extremely dangerous.
A template injection vulnerability in Rejetto HFS ≤2.3m enables unauthenticated remote code execution via crafted HTTP requests. The vulnerability stems from improper template processing that fails to sanitize user input, allowing an attacker to inject and execute arbitrary commands on the host system without authentication.
The full analysis of this CVE is available in Portuguese →