Executive brief
Rejetto HFS, a popular tool for sharing files over the internet, contains a security flaw that allows unauthorized users to access certain internal files. An attacker could exploit this to view specific configuration or data files that are not intended to be public. While the impact is limited to files with a specific format, it could still lead to the exposure of sensitive system information.
Technical details
A path traversal vulnerability (CWE-22) exists in Rejetto HFS versions 3.0.0 through 3.2.0 within the 'lang' query parameter. A remote, unauthenticated attacker can exploit this by submitting specially crafted requests to access files outside of the designated shared directories. The exploit is constrained by the application's logic to only retrieve files that match a specific JSON naming and format pattern, which limits the scope of the data disclosure. The issue is resolved in version 3.2.1.
Affected products
- Rejetto HFS (HTTP File Server) 3.0.0 through 3.2.0
Timeline
- 2026-07-13: advisory: NVD and VulnCheck published the advisory
- 2026-07-13: patched: Version 3.2.1 released to address the issue