Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-servletUpgrade jetty-antUpgrade jetty-startUpgrade jetty-jmxUpgrade jetty-jaspiUpgrade jetty-jspc-maven-pluginUpgrade jetty-jaasUpgrade jetty-projectUpgrade jetty-servletsUpgrade jetty-xmlUpgrade jetty-securityUpgrade jetty-javadocUpgrade jetty-websocket-commonUpgrade jetty-rewriteUpgrade jetty-websocket-servletUpgrade jetty-websocket-parentUpgrade jetty-annotationsUpgrade jetty-clientUpgrade jetty-continuationUpgrade jetty-util-ajaxUpgrade jetty-jndiUpgrade jetty-maven-pluginUpgrade jetty-proxyUpgrade jetty-deployUpgrade jetty-webappUpgrade jetty-runnerUpgrade jetty-httpUpgrade jetty-ioUpgrade jetty-websocket-serverUpgrade jetty-websocket-clientUpgrade jetty-plusUpgrade jetty-serverUpgrade jetty-monitorUpgrade jetty-utilUpgrade jetty-jspUpgrade jetty-websocket-api | Jan 10, 2024 | Sep 15, 2023 |
| Debian | — | Upgrade jetty9 | Oct 2, 2023 | Sep 15, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 15, 2023 |
| Suse | — | Upgrade jetty-jmxUpgrade jetty-annotationsUpgrade jetty-plusUpgrade jetty-servletUpgrade jetty-util-ajaxUpgrade jetty-ioUpgrade jetty-webappUpgrade jetty-deployUpgrade jetty-continuationUpgrade jetty-openidUpgrade jetty-http-spiUpgrade jetty-jndiUpgrade jetty-utilUpgrade jetty-proxyUpgrade jetty-clientUpgrade jetty-quickstartUpgrade jetty-serverUpgrade jetty-jspUpgrade jetty-jaasUpgrade jetty-xmlUpgrade jetty-minimal-javadocUpgrade jetty-servletsUpgrade jetty-startUpgrade jetty-rewriteUpgrade jetty-httpUpgrade jetty-cdiUpgrade jetty-securityUpgrade jetty-antUpgrade jetty-fcgi | Oct 27, 2023 | Sep 15, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub