CRITICAL9.9
GHSA-5f4x-hwv2-w9w2
rejetto HFS vulnerable to OS Command Execution by remote authenticated users
Quick fix
GHSA-5f4x-hwv2-w9w2 — hfs: upgrade to the fixed version with the command below.
npm install hfs@0.52.10Details
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-39943[ADVISORY]
- https://github.com/rejetto/hfs/commit/305381bd36eee074fb238b64302a252668daad1d[WEB]
- https://github.com/rejetto/hfs[PACKAGE]
- https://github.com/rejetto/hfs/compare/v0.52.9...v0.52.10[WEB]
- https://www.rejetto.com/wiki/index.php/HFS:_Working_with_uploads[WEB]