Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-antUpgrade jetty-servletUpgrade jetty-jaspiUpgrade jetty-jmxUpgrade jetty-websocket-commonUpgrade jetty-rewriteUpgrade jetty-websocket-parentUpgrade jetty-jspc-maven-pluginUpgrade jetty-jaasUpgrade jetty-websocket-servletUpgrade jetty-startUpgrade jetty-projectUpgrade jetty-javadocUpgrade jetty-securityUpgrade jetty-xmlUpgrade jetty-servletsUpgrade jetty-webappUpgrade jetty-deployUpgrade jetty-ioUpgrade jetty-jspUpgrade jetty-plusUpgrade jetty-clientUpgrade jetty-serverUpgrade jetty-jndiUpgrade jetty-websocket-apiUpgrade jetty-websocket-clientUpgrade jetty-annotationsUpgrade jetty-util-ajaxUpgrade jetty-runnerUpgrade jetty-proxyUpgrade jetty-httpUpgrade jetty-utilUpgrade jetty-maven-pluginUpgrade jetty-continuationUpgrade jetty-websocket-serverUpgrade jetty-monitor | Jan 10, 2024 | Sep 15, 2023 |
| Debian | — | Upgrade jetty9 | Oct 2, 2023 | Sep 15, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 15, 2023 |
| Suse | — | Upgrade jetty-annotationsUpgrade jetty-deployUpgrade jetty-clientUpgrade jetty-webappUpgrade jetty-continuationUpgrade jetty-http-spiUpgrade jetty-utilUpgrade jetty-openidUpgrade jetty-proxyUpgrade jetty-jmxUpgrade jetty-jndiUpgrade jetty-plusUpgrade jetty-ioUpgrade jetty-quickstartUpgrade jetty-serverUpgrade jetty-util-ajaxUpgrade jetty-servletUpgrade jetty-securityUpgrade jetty-fcgiUpgrade jetty-jspUpgrade jetty-cdiUpgrade jetty-antUpgrade jetty-httpUpgrade jetty-xmlUpgrade jetty-startUpgrade jetty-rewriteUpgrade jetty-jaasUpgrade jetty-servletsUpgrade jetty-minimal-javadoc | Oct 27, 2023 | Sep 15, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub