CVE-2024-1226: Multiple vulnerabilities in Rejetto's Http File Server

Published Mar 12, 2024
·
Updated

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.

Affected Software

1 affected component
Rejetto HTTP File Server

Remediation

Information

The vulnerability has been fixed in subsequent versions. The affected version is not currently supported.

Event History

Mar 12, 2024
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-1226?

CVE-2024-1226 has been classified as a high severity vulnerability due to the potential for unauthorized HTTP response manipulation.

2

How do I fix CVE-2024-1226?

To fix CVE-2024-1226, update your Rejetto Http File Server to the latest version that addresses this vulnerability.

3

What type of attack is associated with CVE-2024-1226?

CVE-2024-1226 can lead to HTTP response splitting attacks, allowing attackers to manipulate HTTP headers.

4

Which software is affected by CVE-2024-1226?

CVE-2024-1226 affects Rejetto Http File Server software.

5

What are the implications of CVE-2024-1226?

The implications of CVE-2024-1226 include potential session hijacking and the ability to execute malicious scripts in the user's browser.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203