CVE-2023-36479: Debian Linux
Low severity, CVSS 3.1. EPSS: 1.2% chance of exploitation in the next 30 days.
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Eclipse Jetty: from 9.0.0, before 9.4.52 (fixed in 9.4.52); from 10.0.0, before 10.0.16 (fixed in 10.0.16); from 11.0.0, before 11.0.16 (fixed in 11.0.16); version 12.0.0 only
Published 2023-09-15. Last modified 2026-06-17.