CVE-2024-23692
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
12Exploited in Wild
YesDecision
Descriptions
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
Rejetto HTTP File Server, hasta la versión 2.3m incluida, es vulnerable a una vulnerabilidad de inyección de plantilla. Esta vulnerabilidad permite que un atacante remoto no autenticado ejecute comandos arbitrarios en el sistema afectado enviando una solicitud HTTP especialmente manipulada. A partir de la fecha de asignación de CVE, Rejetto HFS 2.3m ya no es compatible.
Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2024-01-19 CVE Reserved
- 2024-05-31 CVE Published
- 2024-06-11 First Exploit
- 2024-07-09 Exploited in Wild
- 2024-07-30 KEV Due Date
- 2024-08-19 CVE Updated
- 2024-11-11 EPSS Updated
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
CAPEC
- CAPEC-242: Code Injection
References (13)
URL | Tag | Source |
---|---|---|
https://vulncheck.com/advisories/rejetto-unauth-rce | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rejetto Search vendor "Rejetto" | Http File Server Search vendor "Rejetto" for product "Http File Server" | <= 2.3m Search vendor "Rejetto" for product "Http File Server" and version " <= 2.3m" | - |
Affected
|