Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-36479— Jetty vulnerable to errant command quoting in CGI Servlet

Quick assessment

Affected
eclipse jetty.project
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Eclipse Jetty是Eclipse基金会的一个开源的、基于Java的Web服务器和Java Servlet容器。 Eclipse Jetty Canonical Repository存在安全漏洞,该漏洞源于允许具有非常特定命令结构的Servlet用户执行错误命令。

CVSS 3.5 · Low EPSS 1.16% · P66
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-36479

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Jetty vulnerable to errant command quoting in CGI Servlet
Source: CVE Program / CVE List V5
Vulnerability Description
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
引号语法转义处理不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Eclipse Jetty 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Eclipse Jetty是Eclipse基金会的一个开源的、基于Java的Web服务器和Java Servlet容器。 Eclipse Jetty Canonical Repository存在安全漏洞,该漏洞源于允许具有非常特定命令结构的Servlet用户执行错误命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
eclipse jetty.project >= 9.0.0, <= 9.4.51 -

II. Public POCs for CVE-2023-36479

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-36479

请登录查看更多情报信息。

Patches & Fixes for CVE-2023-36479 (3)

Vendor Advisories for CVE-2023-36479 (2)

Mailing List Discussions for CVE-2023-36479 (1)

Same Patch Batch · eclipse · 2023-09-15 · 3 CVEs total

CVE-2023-40167 5.3 MEDIUM Jetty accepts "+" prefixed value in Content-Length
CVE-2023-41900 3.5 LOW Jetty's OpenId Revoked authentication allows one request

IV. Related Vulnerabilities

V. Comments for CVE-2023-36479

No comments yet


Leave a comment