CVE-2023-36479
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
Published:Sep 15, 2023
Last Modified:Jun 18, 2025
EPS:Sep 15, 2023
EPSS Score:0.00627
CVSS Score:3.5
Affected Products
Vendor
Product
Action
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Eclipse
Product
Jetty
Eclipse
Jetty
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Migration Toolkit Applications
Redhat
Migration Toolkit Applications
Vendor
Redhat
Product
Migration Toolkit Runtimes
Redhat
Migration Toolkit Runtimes
Vendor
Redhat
Product
Satellite
Redhat
Satellite
Vendor
Redhat
Product
Satellite Capsule
Redhat
Satellite Capsule
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
