← KEV catalog
CISA known exploited vulnerability

CVE-2024-23692

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

SOURCE FACT

Rejetto · HTTP File Server

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes

The patched Rejetto HTTP File Server (HFS) is version 3: https://github.com/rejetto/hfs?tab=readme-ov-file#installation, https://www.rejetto.com/hfs/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-23692

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?