rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5f4x-hwv2-w9w2 rejetto HFS vulnerable to OS Command Execution by remote authenticated users
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T04:33:11.602Z

Reserved: 2024-07-04T00:00:00

Link: CVE-2024-39943

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:11.602Z

cve-icon NVD

Status : Modified

Published: 2024-07-04T23:15:09.940

Modified: 2024-11-21T09:28:37.253

Link: CVE-2024-39943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.