CVE-2024-23692: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.
Other sources
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23692?
CVE-2024-23692 is classified with a high severity due to its ability to allow remote, unauthenticated command execution.
How do I fix CVE-2024-23692?
To fix CVE-2024-23692, update Rejetto HTTP File Server to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-23692?
Anyone using Rejetto HTTP File Server version 2.3m or below is affected by CVE-2024-23692.
What type of attack does CVE-2024-23692 enable?
CVE-2024-23692 allows an attacker to execute arbitrary commands on the server through specially crafted HTTP requests.
Is authentication required to exploit CVE-2024-23692?
No, CVE-2024-23692 can be exploited by unauthenticated attackers, making it particularly dangerous.