Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
We have discovered 3,125 live websites that are affected by CVE-2023-36479.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 3,125 live websites (58% of Jetty install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 106 versions ( 47% of all versions) |
| 1,336 websites | |
| 957 websites | |
| 173 websites | |
| 130 websites | |
| 60 websites | |
| 57 websites | |
| 35 websites | |
| 34 websites | |
| 28 websites | |
| 25 websites |
| .com | 1,094 websites |
| .org | 178 websites |
| .net | 141 websites |
| .edu | 111 websites |
| .de | 77 websites |
| .fr | 76 websites |
| .ca | 30 websites |
| .com.au | 19 websites |
| .ru | 18 websites |
| .it | 17 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.***********.net | *,*** | ||
| ******.rocks | **,*** | ||
| *.******.com | **,*** | ||
| *********.******.com | **,*** | ||
| *********.se | **,*** | ||
| **.****************.com | **,*** | ||
| **.******.net | **,*** | ||
| *****.****.edu | **,*** | ||
| *********.******.com | **,*** | ||
| ***.**********.edu | **,*** |
FAQ