
Cloud Vulnerability DB
A community-led vulnerabilities database
An open redirect vulnerability (CVE-2024-1227) was discovered in Rejetto's Http File Server (HFS) version 2.2a build #124. The vulnerability was reported and assigned on February 5, 2024, by the Spanish National Cybersecurity Institute (INCIBE CERT).
The vulnerability has been assigned a CVSS v3.1 base score of 6.5 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N and is categorized as CWE-601. The flaw exists in the HTTP File Server software where user input is not properly validated in URL redirections (INCIBE CERT).
The exploitation of this vulnerability could allow an attacker to create a custom URL and redirect a legitimate page to a malicious site, potentially leading to phishing attacks or other malicious redirections (INCIBE CERT).
The vulnerability has been fixed in subsequent versions of the software. However, it should be noted that the affected version (2.2a build #124) is no longer supported (INCIBE CERT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."