Rejetto HTTP File Server (HFS) Product Security Update Advisory

Overview

 

An update has been released to address vulnerability in the Rejetto HTTP File Server (HFS) product. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

Rejetto HTTP File Server (HFS) versions 2.3m or below

 

Resolved Vulnerabilities

 

Template injection vulnerability in Rejetto HTTP File Server (HFS) (CVE-2024-23692)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest vulnerability patches version.

Rejetto HTTP File Server(HFS ) 3.x version

 

Referenced Sites

 

[1] CVE-2024-23692: Unauthenticated RCE Flaw in Rejetto HTTP File Server, PoC Published

https://securityonline.info/cve-2024-23692-unauthenticated-rce-flaw-in-rejetto-http-file-server-poc-published/

[2] Rejetto HTTP File Server 2.3m Unauthenticated RCE

published https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/

[3] CVE-2024-23692 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23692