Vulnerability record · CVE-2023-36479 · published 15 September 2023
CVE-2023-36479: Eclipse jetty vulnerability
Eclipse · Jetty
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
Description
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/eclipse/jetty.project/pull/9516 | Patch |
| https://github.com/eclipse/jetty.project/pull/9888 | Patch |
| https://github.com/eclipse/jetty.project/pull/9889 | Patch |
| https://github.com/eclipse/jetty.project/security/advisories/GHSA-3gh6-v5v9-6v9j | ExploitPatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html | Mailing ListThird Party Advisory |
| https://www.debian.org/security/2023/dsa-5507 | Mailing ListThird Party Advisory |
| https://github.com/eclipse/jetty.project/pull/9516 | Patch |
| https://github.com/eclipse/jetty.project/pull/9888 | Patch |
| https://github.com/eclipse/jetty.project/pull/9889 | Patch |
| https://github.com/eclipse/jetty.project/security/advisories/GHSA-3gh6-v5v9-6v9j | ExploitPatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html | Mailing ListThird Party Advisory |
| https://www.debian.org/security/2023/dsa-5507 | Mailing ListThird Party Advisory |
Track CVE-2023-36479 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36479), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.