Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Date added
BOD 22-01 due date
CWECWE-1336
RansomwareUnknown
CISA description
Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes & references
The patched Rejetto HTTP File Server (HFS) is version 3: https://github.com/rejetto/hfs?tab=readme-ov-file#installation, https://www.rejetto.com/hfs/