Junglewise Threat Intelligence

CVE-2024-23692: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

CVE-2024-23692 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-07-09

Technologies: Rejetto HTTP File Server. Vendors: Rejetto.

Executive brief

Rejetto HTTP File Server (HFS) contains a template injection vulnerability due to improper neutralization of special elements. A remote, unauthenticated attacker can execute arbitrary commands on the host system by sending a specially crafted HTTP request.

Affected products

  • Rejetto HTTP File Server (HFS) Up to and including 2.3m

Timeline

  • 2024-07-09: disclosed
  • 2024-07-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-07-09: advisory

Related threats