跳转到帖子

SUSE: CVE-2023-36479: SUSE Linux Security Advisory

recommended_posts

发布于
  • Members

SUSE: CVE-2023-36479: SUSE Linux Security Advisory

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
09/15/2023
Created
10/27/2023
Added
10/27/2023
Modified
01/28/2025

Description

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

Solution(s)

  • suse-upgrade-jetty-annotations
  • suse-upgrade-jetty-ant
  • suse-upgrade-jetty-cdi
  • suse-upgrade-jetty-client
  • suse-upgrade-jetty-continuation
  • suse-upgrade-jetty-deploy
  • suse-upgrade-jetty-fcgi
  • suse-upgrade-jetty-http
  • suse-upgrade-jetty-http-spi
  • suse-upgrade-jetty-io
  • suse-upgrade-jetty-jaas
  • suse-upgrade-jetty-jmx
  • suse-upgrade-jetty-jndi
  • suse-upgrade-jetty-jsp
  • suse-upgrade-jetty-minimal-javadoc
  • suse-upgrade-jetty-openid
  • suse-upgrade-jetty-plus
  • suse-upgrade-jetty-proxy
  • suse-upgrade-jetty-quickstart
  • suse-upgrade-jetty-rewrite
  • suse-upgrade-jetty-security
  • suse-upgrade-jetty-server
  • suse-upgrade-jetty-servlet
  • suse-upgrade-jetty-servlets
  • suse-upgrade-jetty-start
  • suse-upgrade-jetty-util
  • suse-upgrade-jetty-util-ajax
  • suse-upgrade-jetty-webapp
  • suse-upgrade-jetty-xml

References

  • https://attackerkb.com/topics/cve-2023-36479
  • CVE - 2023-36479
  • 查看数 705
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…