FAIL › dossier
HTTP File Server
PRODUCT· dossier confidence 80%
HTTP File Server is a web server product that suffered a critical remote code execution vulnerability in 2024, allowing unauthenticated attackers to execute arbitrary commands through template engine injection.
PROFILE
Categoryweb serverWhat they doHTTP File Server is a web server software product.
SECURITY POSTURE
The product has a critical vulnerability allowing remote code execution via template engine injection, indicating a severe security flaw in its core functionality.
Notable failures
- CVE-2024-23692 RCE via template engine injection
Patterns: unpatched edge-device RCEs
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-07-09 | CVE-2024-23692 | high | Rejetto HTTP File Server allows remote, unauthenticated attackers to execute arbitrary commands via template engine injection. |
| 2024-05-31 | CVE-2024-23692 | critical | CVE-2024-23692: Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t |
Open questions: Is HTTP File Server still maintained and patched? · What is the current version of HTTP File Server and its patch status?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:01:02.217897+00:00