LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-23692: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 9, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 30, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-23692 to its Known Exploited Vulnerabilities catalog on Jul 9, 2024, with a federal patch deadline of Jul 30, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the…

CVE-2024-23692 is an improper neutralization of special elements used in a template engine vulnerability in Rejetto HTTP File Server. A remote, unauthenticated attacker can send a specially crafted HTTP request that causes the product to execute commands on the affected system. This matters because the attack requires no credentials and can give an outsider full control of the host running the file server, which often holds shared files and may sit on internal networks.

Defenders should treat any internet-reachable or poorly segmented instance as high priority until the vendor-recommended mitigations are confirmed in place or the product is removed.

How it works

The underlying weakness is CWE-1336: improper neutralization of special elements used in a template engine. Template engines evaluate or render content that can include user-supplied data. When that data is not correctly sanitized, an attacker can inject template directives or expressions that the engine then executes with the privileges of the server process.

In this case the CISA summary states that a specially crafted HTTP request is sufficient. The request reaches a code path that feeds attacker-controlled input into the template engine without adequate neutralization, resulting in command execution. Exact request format, payload construction, and any required parameters are not provided here; teams must obtain those details only from the vendor advisory or trusted analysis that cites it. No authentication is required, so the attack surface is any network-accessible instance of the product.

Am I affected? How to find it in your systems

Rejetto HTTP File Server is typically deployed as a lightweight file-sharing service on Windows or other hosts, often by small teams or for temporary sharing. It may appear as a standalone executable or service listening on HTTP/HTTPS ports.

Specifics of affected versions and exact log signatures must be verified against the vendor advisory.

How to remediate

The primary action is to apply the mitigations or updates published by the vendor, exactly as instructed. CISA’s required action is to apply those mitigations or to discontinue use of the product if mitigations are unavailable.

Do not rely on unofficial patches or third-party “fixes” that have not been validated against the vendor guidance.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps lower risk but do not eliminate it; schedule the permanent fix as soon as possible.

If your data may have been exposed

Vulnerabilities that allow unauthenticated remote command execution are frequently used to establish persistence, steal files, or move laterally. Although ransomware use of this specific CVE is not documented, any successful exploitation can lead to data theft or further compromise. Review access logs and host forensics for signs of intrusion. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRejetto · HTTP File Server
WeaknessCWE-1336
Added to CISA KEVJul 9, 2024
Federal patch deadlineJul 30, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities