CVE-2023-36479

Jetty vulnerable to errant command quoting in CGI Servlet

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.


We have discovered 3,281 live websites that are affected by CVE-2023-36479.

Run a Free Instant Scan




Affected Software

Product  Jetty
Category Web Servers
Vulnerable Domains3,281 live websites (100% of Jetty install base)
Vulnerable Versions
  • from 9 through 9.4.51
  • from 10 through 10.0.15
  • from 11 through 11.0.15
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-149 Improper Neutralization of Quoting Syntax



Details

  • Published - Sep 15, 2023
  • Updated - Jun 18, 2025

Website Distribution by Country

Number of websites using CVE-2023-36479
United States1,426 websites



Netherlands955 websites
Germany176 websites
France145 websites
Canada62 websites
China60 websites
Australia42 websites
Italy42 websites
Singapore29 websites
GB26 websites

Website Distribution by TLD

Number of websites using CVE-2023-36479
.com1,135 websites
.org225 websites
.net139 websites
.edu128 websites
.fr90 websites
.de77 websites
.ca31 websites
.nl23 websites
.it22 websites
.com.br20 websites

Websites affected by CVE-2023-36479

Top websites that are affected by CVE-2023-36479. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.***********.net United States*,***
******.rocks Netherlands**,***
*.******.com United States**,***
*********.******.com United States**,***
*********.se Sweden**,***
**.****************.com United States**,***
**.******.net United States**,***
*****.****.edu United States**,***
*********.******.com United States**,***
***.**********.edu United States**,***
See full domain list

FAQ

CVE-2023-36479 is Improper Neutralization of Quoting Syntax in Jetty
A total of 3,281 websites have been identified as vulnerable to CVE-2023-36479, based on global website indexing conducted by WebTechSurvey.
The Jetty is affected by the CVE-2023-36479 vulnerability.
Jetty versions up to and including 11.0.15 are vulnerable to CVE-2023-36479.