Логотип exploitDog
bind: "CVE-2023-36479"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-36479"

Количество 9

Количество 9

ubuntu логотип

CVE-2023-36479

почти 2 года назад

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

CVSS3: 3.5
EPSS: Низкий
redhat логотип

CVE-2023-36479

почти 2 года назад

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2023-36479

почти 2 года назад

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2023-36479

почти 2 года назад

Eclipse Jetty Canonical Repository is the canonical repository for the ...

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3gh6-v5v9-6v9j

почти 2 года назад

Jetty vulnerable to errant command quoting in CGI Servlet

CVSS3: 3.5
EPSS: Низкий
fstec логотип

BDU:2024-05833

почти 2 года назад

Уязвимость контейнера сервлетов Eclipse Jetty, связанная с неправильной нейтрализацией синтаксиса цитирования, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20240730-08

11 месяцев назад

Множественные уязвимости jetty

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4210-1

больше 1 года назад

Security update for jetty-minimal

EPSS: Низкий
redos логотип

ROS-20240409-12

около 1 года назад

Множественные уязвимости apache-kafka

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-36479

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

CVSS3: 3.5
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2023-36479

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

CVSS3: 3.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-36479

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

CVSS3: 3.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2023-36479

Eclipse Jetty Canonical Repository is the canonical repository for the ...

CVSS3: 3.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-3gh6-v5v9-6v9j

Jetty vulnerable to errant command quoting in CGI Servlet

CVSS3: 3.5
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-05833

Уязвимость контейнера сервлетов Eclipse Jetty, связанная с неправильной нейтрализацией синтаксиса цитирования, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.3
1%
Низкий
почти 2 года назад
redos логотип
ROS-20240730-08

Множественные уязвимости jetty

CVSS3: 5.3
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2023:4210-1

Security update for jetty-minimal

больше 1 года назад
redos логотип
ROS-20240409-12

Множественные уязвимости apache-kafka

CVSS3: 9.8
около 1 года назад

Уязвимостей на страницу