NA

CVE-2023-36479

Published: 15/09/2023 Updated: 16/10/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Description<!---->A flaw was found in Jetty's CGI servlet which permits incorrect command execution in specific circumstances such as requests with certain characters in requested filenames. This issue could allow an malicious user to run permitted commands other than the one requested.A flaw was found in Jetty's CGI servlet which permits incorrect command execution in specific circumstances such as requests with certain characters in requested filenames. This issue could allow an malicious user to run permitted commands other than the one requested.

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse jetty 12.0.0

eclipse jetty

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

Vendor Advisories

Synopsis Critical: Red Hat Fuse 7121 release and security update Type/Severity Security Advisory: Critical Topic A minor version update (from 712 to 7121) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...
Multiple security vulnerabilities were found in Jetty, a Java based web server and servlet engine The orgeclipsejettyservletsCGI class has been deprecated It is potentially unsafe to use it The upstream developers of Jetty recommend to use Fast CGI instead See also CVE-2023-36479 CVE-2023-26048 In affected versions servlets with multi ...
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project Users of the CgiServlet with a very specific command structure may have the wrong command executed If a user sends a request to a orgeclipsejettyservletsCGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in q ...
Description<!---->A flaw was found in Jetty's CGI servlet which permits incorrect command execution in specific circumstances such as requests with certain characters in requested filenames This issue could allow an attacker to run permitted commands other than the one requestedA flaw was found in Jetty's CGI servlet which permits incorrect comma ...