Description
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5f4x-hwv2-w9w2 | rejetto HFS vulnerable to OS Command Execution by remote authenticated users |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T04:33:11.602Z
Reserved: 2024-07-04T00:00:00.000Z
Link: CVE-2024-39943
Updated: 2024-08-02T04:33:11.602Z
Status : Modified
Published: 2024-07-04T23:15:09.940
Modified: 2024-11-21T09:28:37.253
Link: CVE-2024-39943
No data.
OpenCVE Enrichment
No data.
Github GHSA