Executive brief
rejetto HFS is a web-based file server application that allows users to share folders and files over HTTP. The vulnerability allows authenticated users with upload permissions to execute arbitrary operating system commands on the server by exploiting improper shell command execution. An attacker could gain full control of the server and access sensitive data or disrupt service availability.
Technical details
rejetto HFS contains an OS command injection vulnerability in its upload handling functionality on POSIX systems (Linux, UNIX, macOS). The root cause is the use of execSync instead of spawnSync in Node.js when executing the df command to check disk space. The execSync function invokes a shell to execute the command, which is vulnerable to shell metacharacter injection. An authenticated attacker with upload permissions can craft a malicious filename or file metadata containing shell metacharacters (e.g., backticks, command substitution) to inject and execute arbitrary commands with the privileges of the HFS process. The vulnerability requires prior authentication and upload permissions, limiting the attack surface to authenticated users. The fix, released in version 0.52.10, replaces execSync with spawnSync to avoid shell interpretation. Affected versions: all releases before 0.52.10.
Affected products
- rejetto HFS before 0.52.10
Timeline
- 2024-07-04: disclosed: CVE-2024-39943 published on NVD
- 2024-07-03: patched: Fix committed and version 0.52.10 released