MEDIUMMaven

Jetty vulnerable to errant command quoting in CGI Servlet

Jetty vulnerable to errant command quoting in CGI Servlet

CVE-2023-36479Published 3 years agoUpdated 5 days agoSource: OSV

Affected packages

  • org.eclipse.jetty.ee10:jetty-ee10-servletsbefore 12.0.0-beta2
  • org.eclipse.jetty.ee8:jetty-ee8-servletsbefore 12.0.0-beta2
  • org.eclipse.jetty.ee9:jetty-ee9-servletsbefore 12.0.0-beta2
  • org.eclipse.jetty:jetty-servlets9.0.0 → 9.4.52

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Jetty vulnerable to errant command quoting in CGI Servlet | HackTribune