Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-startUpgrade jetty-servletUpgrade jetty-antUpgrade jetty-websocket-parentUpgrade jetty-jmxUpgrade jetty-jspc-maven-pluginUpgrade jetty-servletsUpgrade jetty-xmlUpgrade jetty-projectUpgrade jetty-jaasUpgrade jetty-securityUpgrade jetty-rewriteUpgrade jetty-javadocUpgrade jetty-websocket-servletUpgrade jetty-websocket-commonUpgrade jetty-jaspiUpgrade jetty-jspUpgrade jetty-monitorUpgrade jetty-continuationUpgrade jetty-annotationsUpgrade jetty-webappUpgrade jetty-websocket-apiUpgrade jetty-clientUpgrade jetty-deployUpgrade jetty-websocket-serverUpgrade jetty-util-ajaxUpgrade jetty-ioUpgrade jetty-maven-pluginUpgrade jetty-plusUpgrade jetty-serverUpgrade jetty-websocket-clientUpgrade jetty-jndiUpgrade jetty-utilUpgrade jetty-proxyUpgrade jetty-runnerUpgrade jetty-http | Jan 10, 2024 | Sep 15, 2023 |
| Debian | — | Upgrade jetty9 | Oct 2, 2023 | Sep 15, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 15, 2023 |
| Suse | — | Upgrade jetty-proxyUpgrade jetty-jndiUpgrade jetty-openidUpgrade jetty-ioUpgrade jetty-continuationUpgrade jetty-jmxUpgrade jetty-clientUpgrade jetty-plusUpgrade jetty-utilUpgrade jetty-http-spiUpgrade jetty-webappUpgrade jetty-annotationsUpgrade jetty-servletUpgrade jetty-deployUpgrade jetty-quickstartUpgrade jetty-serverUpgrade jetty-util-ajaxUpgrade jetty-servletsUpgrade jetty-securityUpgrade jetty-fcgiUpgrade jetty-antUpgrade jetty-cdiUpgrade jetty-jaasUpgrade jetty-minimal-javadocUpgrade jetty-jspUpgrade jetty-xmlUpgrade jetty-rewriteUpgrade jetty-httpUpgrade jetty-start | Oct 27, 2023 | Sep 15, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub