Vulnerability Description
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rejetto | Http File Server | < 0.52.10 |
Related Weaknesses (CWE)
References
- https://github.com/rejetto/hfs/commit/305381bd36eee074fb238b64302a252668daad1dPatch
- https://github.com/rejetto/hfs/compare/v0.52.9...v0.52.10Patch
- https://www.rejetto.com/wiki/index.php/HFS:_Working_with_uploadsProduct
- https://github.com/rejetto/hfs/commit/305381bd36eee074fb238b64302a252668daad1dPatch
- https://github.com/rejetto/hfs/compare/v0.52.9...v0.52.10Patch
- https://www.rejetto.com/wiki/index.php/HFS:_Working_with_uploadsProduct
FAQ
What is CVE-2024-39943?
CVE-2024-39943 is a vulnerability with a CVSS score of 9.9 (CRITICAL). rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell i...
How severe is CVE-2024-39943?
CVE-2024-39943 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-39943?
Check the references section above for vendor advisories and patch information. Affected products include: Rejetto Http File Server.