Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.151004
Categoría:Web Servers
Título:Eclipse Jetty CgiServlet Vulnerability (GHSA-3gh6-v5v9-6v9j) - Windows
Resumen:Eclipse Jetty is prone to a vulnerability in the CgiServlet.
Descripción:Summary:
Eclipse Jetty is prone to a vulnerability in the CgiServlet.

Vulnerability Insight:
Users of the CgiServlet with a very specific command structure
may have the wrong command executed. If a user sends a request to a
org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will
escape the command by wrapping it in quotation marks. This wrapped command, plus an optional
command prefix, will then be executed through a call to Runtime.exec. If the original binary name
provided by the user contains a quotation mark followed by a space, the resulting command line
will contain multiple tokens instead of one.

Affected Software/OS:
Eclipse Jetty version 9.0.0 through 9.4.51, 10.0.0 through
10.0.15 and 11.0.0 through 11.0.15.

Solution:
Update to version 9.4.52, 10.0.16, 11.0.16 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2023-36479
Debian Security Information: DSA-5507 (Google Search)
https://www.debian.org/security/2023/dsa-5507
https://github.com/eclipse/jetty.project/pull/9516
https://github.com/eclipse/jetty.project/pull/9888
https://github.com/eclipse/jetty.project/pull/9889
https://github.com/eclipse/jetty.project/security/advisories/GHSA-3gh6-v5v9-6v9j
https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html
CopyrightCopyright (C) 2023 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.