Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)#19240
Merged
bwatters-r7 merged 3 commits intorapid7:masterfrom Jun 11, 2024
Merged
Conversation
jvoisin
reviewed
Jun 7, 2024
documentation/modules/exploit/windows/http/rejetto_hfs_rce_cve_2024_23692.md
Outdated
Show resolved
Hide resolved
modules/exploits/windows/http/rejetto_hfs_rce_cve_2024_23692.rb
Outdated
Show resolved
Hide resolved
Contributor
|
@msjenkins-r7 test this please |
Contributor
|
Not sure why Linux sanity tests are failing. It appears not to have retested from my earlier comment. |
Contributor
|
@msjenkins-r7 retest this please |
Contributor
Windows 10x64 22H2 |
Contributor
|
@sfewer-r7 I'll get this landed once the minor doc suggestions are finished. |
…_2024_23692.md fix a typo in the documentation. Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com>
improve documentation guidance to mention upgrading to a newer supported version (as 2.x is no longer supported) Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com>
Contributor
Author
|
Thanks @bwatters-r7, I have committed those 2 documentation changes so we should be good here :) |
Contributor
Release NotesAdds an exploit module for CVE-2024-23692, an unauthorized SSTI in the Rejetto HTTP File Server (HFS). |
|
Running automatic check ("set AutoCheck false" to disable) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request adds an exploit module for CVE-2024-23692, a unauth SSTI in the Rejetto HTTP File Server (HFS).
Original finder has a blog post here, along with a redacted PoC: https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/
I wrote a short AKB assessment here: https://attackerkb.com/assessments/f5c5359d-2446-4e33-a1a2-6a66aa2fb5f6
Tested against versions:
Example usage: