CVE-2023-36479

Jetty vulnerable to errant command quoting in CGI Servlet

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.


We have discovered 3,125 live websites that are affected by CVE-2023-36479.

Run a Free Instant Scan




Affected Software

Product  Jetty
Category Web Servers
Vulnerable Domains3,125 live websites (58% of Jetty install base)
Vulnerable Versions
  • from 9 through 9.4.51
  • from 10 through 10.0.15
  • from 11 through 11.0.15
Vulnerable Versions Count106 versions ( 47% of all versions)


Common Weakness Enumeration

CWE-149 Improper Neutralization of Quoting Syntax



Details

  • Published - Sep 15, 2023
  • Updated - Jun 18, 2025

Website Distribution by Country

Number of websites using CVE-2023-36479
United States1,336 websites



Netherlands957 websites
Germany173 websites
France130 websites
Canada60 websites
China57 websites
Italy35 websites
Australia34 websites
GB28 websites
Singapore25 websites

Website Distribution by TLD

Number of websites using CVE-2023-36479
.com1,094 websites
.org178 websites
.net141 websites
.edu111 websites
.de77 websites
.fr76 websites
.ca30 websites
.com.au19 websites
.ru18 websites
.it17 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-36479

Top websites that are affected by CVE-2023-36479. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.***********.net United States*,***
******.rocks Netherlands**,***
*.******.com United States**,***
*********.******.com United States**,***
*********.se Sweden**,***
**.****************.com United States**,***
**.******.net United States**,***
*****.****.edu United States**,***
*********.******.com United States**,***
***.**********.edu United States**,***
See full domain list

FAQ

CVE-2023-36479 is Improper Neutralization of Quoting Syntax in Jetty
A total of 3,125 websites have been identified as vulnerable to CVE-2023-36479, based on global website indexing conducted by WebTechSurvey.
The Jetty is affected by the CVE-2023-36479 vulnerability.
Jetty versions up to and including 11.0.15 are vulnerable to CVE-2023-36479.