Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-javadocUpgrade jetty-securityUpgrade jetty-antUpgrade jetty-xmlUpgrade jetty-websocket-parentUpgrade jetty-startUpgrade jetty-websocket-servletUpgrade jetty-projectUpgrade jetty-jmxUpgrade jetty-jaasUpgrade jetty-jspc-maven-pluginUpgrade jetty-servletsUpgrade jetty-servletUpgrade jetty-websocket-commonUpgrade jetty-jaspiUpgrade jetty-rewriteUpgrade jetty-maven-pluginUpgrade jetty-utilUpgrade jetty-plusUpgrade jetty-deployUpgrade jetty-clientUpgrade jetty-websocket-serverUpgrade jetty-annotationsUpgrade jetty-jndiUpgrade jetty-websocket-apiUpgrade jetty-websocket-clientUpgrade jetty-serverUpgrade jetty-webappUpgrade jetty-continuationUpgrade jetty-monitorUpgrade jetty-runnerUpgrade jetty-proxyUpgrade jetty-ioUpgrade jetty-httpUpgrade jetty-jspUpgrade jetty-util-ajax | Jan 10, 2024 | Sep 15, 2023 |
| Debian | — | Upgrade jetty9 | Oct 2, 2023 | Sep 15, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 15, 2023 |
| Suse | — | Upgrade jetty-httpUpgrade jetty-cdiUpgrade jetty-startUpgrade jetty-fcgiUpgrade jetty-antUpgrade jetty-rewriteUpgrade jetty-servletsUpgrade jetty-jspUpgrade jetty-jaasUpgrade jetty-securityUpgrade jetty-xmlUpgrade jetty-minimal-javadocUpgrade jetty-deployUpgrade jetty-serverUpgrade jetty-jndiUpgrade jetty-proxyUpgrade jetty-utilUpgrade jetty-util-ajaxUpgrade jetty-quickstartUpgrade jetty-plusUpgrade jetty-annotationsUpgrade jetty-servletUpgrade jetty-clientUpgrade jetty-openidUpgrade jetty-jmxUpgrade jetty-ioUpgrade jetty-continuationUpgrade jetty-webappUpgrade jetty-http-spi | Oct 27, 2023 | Sep 15, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub