StackRadar

CVE-2023-36479

Low

Advisory

Published 14 Sept 2023In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.5
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
88
of 17,781 indexed, latest versions
Container images
80
deployed by those charts
Fix available
1 of 1
affected package

Jetty vulnerable to errant command quoting in CGI Servlet

Carried by container images the latest versions of 88 of 17,781 indexed charts deploy, on 80 images.

Affected packageAffected versionsFixed inImages
jetty-servletsmaven9.2.5.v20141112, 9.3.11.v20160721, 9.3.20.v20170531, 9.3.24.v20180605+27 more9.4.52, 10.0.1680
OSV records
GHSA-3gh6-v5v9-6v9j

Charts affected

88 by stars
ChartLatestAffected imagesRadar Score
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
jetty-servlets@9.3.27.v20190418
9.4.52

Open the chart page →

6,174
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

1,754
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
jetty-servlets@9.3.24.v20180605
9.4.52

Open the chart page →

10,777
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-servlets@9.4.30.v20200611
9.4.52

Open the chart page →

12,856
spring-boot-chartjhidalgo3-githubVerified publisher4.0.01 of 1See more

spring-boot-chart jhidalgo3-github 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
jhidalgo3/spring-echo-example:lateste08733191ea0
jetty-servlets@9.4.35.v20201120
9.4.52

Open the chart page →

1,703
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

444
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
jetty-servlets@9.4.30.v20200611
9.4.52

Open the chart page →

2,427
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jetty-servlets@9.4.33.v20201020
9.4.52

Open the chart page →

2,391
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-servlets@9.4.10.v20180503
9.4.52

Open the chart page →

15,855
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
jetty-servlets@9.4.12.v20180830
9.4.52

Open the chart page →

43,341
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

12,108
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
jetty-servlets@9.4.43.v20210629
9.4.52

Open the chart page →

16,198
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

19,226
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
jetty-servlets@9.4.43.v20210629
9.4.52

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
jetty-servlets@9.4.44.v20210927
9.4.52

Open the chart page →

15,675
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jetty-servlets@9.4.32.v20200930
9.4.52

Open the chart page →

55,726
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-servlets@9.4.43.v20210629
9.4.52

Open the chart page →

4,547
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
jetty-servlets@9.4.51.v20230217
9.4.52

Open the chart page →

9,005
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
jetty-servlets@9.4.22.v20191022
9.4.52

Open the chart page →

12,927
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
jetty-servlets@9.4.43.v20210629
9.4.52

Open the chart page →

41,044
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
jetty-servlets@9.4.45.v20220203
9.4.52

Open the chart page →

13,607
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
jetty-servlets@9.4.45.v20220203
9.4.52

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
jetty-servlets@9.4.45.v20220203
9.4.52

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
jetty-servlets@9.4.45.v20220203
9.4.52

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
jetty-servlets@9.4.45.v20220203
9.4.52

Open the chart page →

13,100
jmxproxypndaproject0.1.01 of 1See more

jmxproxy pndaproject 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
gradiant/jmxproxy:3.4.045eceb1bc55c
jetty-servlets@9.4.8.v20171121
9.4.52

Open the chart page →

4,177
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
jetty-servlets@9.4.45.v20220203
9.4.52

Open the chart page →

3,051
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jetty-servlets@9.4.51.v20230217
9.4.52

Open the chart page →

1,528
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
jetty-servlets@9.4.20.v20190813
9.4.52

Open the chart page →

10,967
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
jetty-servlets@9.4.51.v20230217
9.4.52

Open the chart page →

4,946
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-servlets@9.4.11.v20180605
9.4.52

Open the chart page →

3,164
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jetty-servlets@9.4.44.v20210927
9.4.52

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jetty-servlets@9.4.44.v20210927
9.4.52

Open the chart page →

8,806
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jetty-servlets@9.4.48.v20220622
9.4.52

Open the chart page →

18,756
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-36479.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jetty-servlets@9.4.44.v20210927
9.4.52

Open the chart page →

9,397

Container images carrying it

80 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gurolakman/smsf-momt:1.0.4ce23b20a8a17
jetty-servlets@9.4.45.v20220203
9.4.52
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
jetty-servlets@9.4.45.v20220203
9.4.52
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
jetty-servlets@9.4.45.v20220203
9.4.52
1
gurolakman/ussigw-core:1.0.48739565c3ea2
jetty-servlets@9.4.45.v20220203
9.4.52
1
hazelcast/management-center:5.3.2f9d34300d330
jetty-servlets@10.0.15
10.0.16
1
iamdorsah/bastillion:v0.1db83a0254d81
jetty-servlets@9.4.45.v20220203
9.4.52
1
jhidalgo3/spring-echo-example:lateste08733191ea0
jetty-servlets@9.4.35.v20201120
9.4.52
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
jetty-servlets@9.4.18.v20190429
9.4.52
1
library/solr:8.7.0d124efd81fbb
jetty-servlets@9.4.27.v20200227
9.4.52
1
library/storm:2.4.0bd5d420506d6
jetty-servlets@9.4.14.v20181114
9.4.52
1
lightbend/spark-history-server:2.4.00bedf37f428a
jetty-servlets@9.3.24.v20180605
9.4.52
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jetty-servlets@9.4.33.v20201020
9.4.52
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
jetty-servlets@9.4.12.v20180830
9.4.52
1
onosproject/onos:2.2.144914a8d4b3f
jetty-servlets@9.4.22.v20191022
9.4.52
1
openhab/openhab:3.2.0d0aa4af452c1
jetty-servlets@9.4.43.v20210629
9.4.52
1
rodolpheche/wiremock:2.27.22328a9fce2bf
jetty-servlets@9.4.30.v20200611
9.4.52
1
rundeck/rundeck:3.2.74d64fe56f767
jetty-servlets@9.4.20.v20190813
9.4.52
1
rundeck/rundeck:3.0.16b13e8059ad72
jetty-servlets@9.4.11.v20180605
9.4.52
1
sismics/docs:v1.10f4b0ef019cf1
jetty-servlets@9.4.36.v20210114
9.4.52
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
jetty-servlets@9.2.5.v20141112
9.4.52
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
jetty-servlets@9.3.11.v20160721
9.4.52
1
sonatype/nexus3:3.58.1586060431b64
jetty-servlets@9.4.51.v20230217
9.4.52
1
sslhep/hive-metastore:3.1.39e80af083079
jetty-servlets@9.3.20.v20170531
9.4.52
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jetty-servlets@9.4.48.v20220622
9.4.52
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jetty-servlets@9.4.6.v20170531
9.4.52
1
voltha/voltha-onos:5.1.8e038acb950d3
jetty-servlets@9.4.43.v20210629
9.4.52
1
vromero/activemq-artemis:2.16.0408d6a46b153
jetty-servlets@9.4.27.v20200227
9.4.52
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-servlets@9.4.30.v20200611
9.4.52
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-servlets@9.4.44.v20210927
9.4.52
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-servlets@9.4.11.v20180605
9.4.52
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.