Back to Labs
Security Advisory

CVE-2024-23692

About

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

Weakness (CWE):CWE-1336CWE-94

Rainforest analyst review

Rejetto HTTP File Server (HFS) up to and including 2.3m contains a server-side template injection flaw. HFS uses a template engine to render its web pages, and user-controllable input reaches that engine without sanitization, so an unauthenticated attacker can send a specially crafted HTTP request whose payload is evaluated as a template expression and executed as an operating-system command on the host. No login and no interaction are required.

HFS is a lightweight file-sharing server popular with individuals and small operations for quickly exposing files over the web, which means instances are frequently internet-facing and rarely maintained, and 2.3m is end-of-life with no support. Public exploits appeared fast and the flaw was quickly adopted for cryptomining, botnet, and malware delivery campaigns against exposed hosts. Because the vulnerable branch is abandoned, the real fix is migrating off HFS 2.3m to the maintained 0.52+ line or another product; in the interim remove exposed instances from the internet and check compromised-looking hosts for injected commands and dropped payloads.

References

Related CVEs

Frequently asked questions

What is CVE-2024-23692?

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

How severe is CVE-2024-23692?

CVE-2024-23692 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2024-23692 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2024-23692?

Public advisories list the following as affected: http file server. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2024-23692?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email