CVE-2024-23692
Rejetto HTTP File Server up to version 2.3m contains a critical template injection flaw that lets attackers run arbitrary commands on the server. The vulnerability is remote, requires no authentication or user interaction, and is no longer supported by the vendor.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Rejetto HTTP File Server version 2.3m and earlier. Administrators who run the server are the typical users.
Real-world impact
An attacker can execute any command on the affected system, giving full control over files, processes, and network resources. This could lead to data theft, system compromise, or the server being used for further attacks.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable from the network, requires no privileges, and can compromise confidentiality, integrity, and availability of the entire system.
What to do about it
- ›Apply vendor mitigations if available
- ›Discontinue use of the product if no mitigations are available
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
CISA KEV required action
Timeline
- May 31, 2024 · May 31, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Jul 9, 2024 · Jul 9, 2024Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 30, 2024 · Jul 30, 2024CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 11, 2026 · Aug 11, 2026Advisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/rapid7/metasploit-framework…exploitissue trackingpatch
- mohemiv.com/all/rejetto-http-file-serve…exploit
- vulncheck.com/advisories/rejetto-unauth-r…third party advisory
- vicarius.io/vsociety/posts/cve-2024-236…exploitthird party advisory
- vicarius.io/vsociety/posts/cve-2024-236…exploitthird party advisory
- vicarius.io/vsociety/posts/unauthentica…exploitthird party advisory
- cisa.gov/known-exploited-vulnerabili…us government resource