Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-servletsUpgrade jetty-websocket-parentUpgrade jetty-startUpgrade jetty-jaasUpgrade jetty-xmlUpgrade jetty-jmxUpgrade jetty-jspc-maven-pluginUpgrade jetty-jaspiUpgrade jetty-securityUpgrade jetty-antUpgrade jetty-servletUpgrade jetty-javadocUpgrade jetty-websocket-servletUpgrade jetty-websocket-commonUpgrade jetty-rewriteUpgrade jetty-projectUpgrade jetty-runnerUpgrade jetty-httpUpgrade jetty-plusUpgrade jetty-proxyUpgrade jetty-webappUpgrade jetty-jspUpgrade jetty-monitorUpgrade jetty-jndiUpgrade jetty-serverUpgrade jetty-deployUpgrade jetty-util-ajaxUpgrade jetty-continuationUpgrade jetty-websocket-serverUpgrade jetty-maven-pluginUpgrade jetty-websocket-apiUpgrade jetty-websocket-clientUpgrade jetty-annotationsUpgrade jetty-utilUpgrade jetty-clientUpgrade jetty-io | Jan 10, 2024 | Sep 15, 2023 |
| Debian | — | Upgrade jetty9 | Oct 2, 2023 | Sep 15, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 15, 2023 |
| Suse | — | Upgrade jetty-servletsUpgrade jetty-minimal-javadocUpgrade jetty-jspUpgrade jetty-jaasUpgrade jetty-fcgiUpgrade jetty-rewriteUpgrade jetty-cdiUpgrade jetty-startUpgrade jetty-httpUpgrade jetty-xmlUpgrade jetty-antUpgrade jetty-securityUpgrade jetty-deployUpgrade jetty-util-ajaxUpgrade jetty-annotationsUpgrade jetty-servletUpgrade jetty-continuationUpgrade jetty-jndiUpgrade jetty-utilUpgrade jetty-proxyUpgrade jetty-ioUpgrade jetty-jmxUpgrade jetty-http-spiUpgrade jetty-clientUpgrade jetty-openidUpgrade jetty-serverUpgrade jetty-quickstartUpgrade jetty-plusUpgrade jetty-webapp | Oct 27, 2023 | Sep 15, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub