{"schema_version":"1.9.0","id":"CVE-2023-36479","published":"2023-09-15T18:37:35.948Z","modified":"2026-09-06T03:45:25.676040982Z","aliases":["GHSA-3gh6-v5v9-6v9j"],"related":["CGA-4jch-hfv5-2v2v","SUSE-SU-2023:4210-1","openSUSE-SU-2024:13329-1"],"summary":"Jetty vulnerable to errant command quoting in CGI Servlet","details":"Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jetty/jetty.project","events":[{"introduced":"1237b739c787a75a5f9e1f495b3f2c8284761499"},{"fixed":"abdcda73818a1a2c705da276edb0bf6581e7997e"},{"introduced":"b9645a17373e4e9b7f30b6c0a07defcea2cb660b"},{"fixed":"a2735a9ae9d1afc124974253f1e223e5678be1f4"},{"introduced":"432f896d7a4555fcc81f38108757ea0aca8788e6"},{"fixed":"bedff458c4dd1a716d59e17b8cb0d2042eeab291"},{"introduced":"8fe4dbc6ddb14403a9fcb3be8b84959741910a95"},{"last_affected":"f98b345a28fcefbf1fa8e16dc4b44605b68f2c62"}],"database_specific":{"cpe":["cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.0:alpha2:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.0:alpha3:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.0:beta0:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.0:beta1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0.0"},{"fixed":"9.4.52"},{"introduced":"10.0.0"},{"fixed":"10.0.16"},{"introduced":"11.0.0"},{"fixed":"11.0.16"},{"introduced":"12.0.0-alpha1"},{"last_affected":"12.0.0-alpha1"},{"introduced":"12.0.0-alpha2"},{"last_affected":"12.0.0-alpha2"},{"introduced":"12.0.0-alpha3"},{"last_affected":"12.0.0-alpha3"},{"introduced":"12.0.0-beta0"},{"last_affected":"12.0.0-beta0"},{"introduced":"12.0.0-beta1"},{"last_affected":"12.0.0-beta1"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["12.0.0-alpha1","12.0.0-alpha2","12.0.0-alpha3","12.0.0-beta0","12.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-36479.json"}}],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36479.json"},{"type":"ADVISORY","url":"https://github.com/eclipse/jetty.project/security/advisories/GHSA-3gh6-v5v9-6v9j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36479"},{"type":"ADVISORY","url":"https://www.debian.org/security/2023/dsa-5507"},{"type":"FIX","url":"https://github.com/eclipse/jetty.project/pull/9516"},{"type":"FIX","url":"https://github.com/eclipse/jetty.project/pull/9888"},{"type":"FIX","url":"https://github.com/eclipse/jetty.project/pull/9889"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-149"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36479.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N"}]}