Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-50379

59
FAUCET Score

CVE-2024-50379 is a critical Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Apache Tomcat (versions 11.0.0-M1 to 11.0.1, 10.1.0-M1 to 10.1.33, and 9.0.0.M1 to 9.0.97, including some EOL versions), allowing Remote Code Execution (RCE) on case-insensitive file systems when the default servlet is configured for write access. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a low attack complexity and requires no user interaction, enabling full compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, there is public exploit code available on GitHub and significant community discussion, indicating a high potential for active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.0.0, < 9.0.98CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 10.1.0, < 10.1.34CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 11.0.0, < 11.0.2CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
>= 10.1.0-M1, <= 10.1.33CPE match
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
44.31%
Probability of exploitation in next 30 days
EPSS Percentile
98.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.4431 is in the 96th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 11.0.2
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 10.1.34
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 11.0.2
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 9.0.98
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 10.1.34
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 9.0.98
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el9_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 7Fixed in: jws5-tomcat-0:9.0.87-6.redhat_00006.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 8Fixed in: jws5-tomcat-0:9.0.87-6.redhat_00006.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6.0 on RHEL 8Fixed in: jws6-tomcat-0:10.1.8-15.redhat_00022.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6.0 on RHEL 9Fixed in: jws6-tomcat-0:10.1.8-15.redhat_00022.1.el9jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 9Fixed in: jws5-tomcat-0:9.0.87-6.redhat_00006.1.el9jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: tomcat-1:9.0.87-1.el8_10.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el8_8.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: tomcat-1:9.0.87-2.el9_5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: pki-servlet-engine-1:9.0.50-1.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el9_2.3
View patch
barracudavendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
freshrssvendor investigatingvia llm_extracted
qdrantvendor investigatingvia llm_extracted
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pki-servlet-engine
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: tomcat
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6/pki-servlet-engine

Vendor Advisories (10)

qdrantllm-qdrant-ab83110a388905f9

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
boschllm-bosch-0156a5440e8f8201

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
freshrssllm-freshrss-4c5d10c943020702

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
barracudallm-barracuda-80df225defecf766

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
symantecllm-symantec-7b53d7b2901ab916

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
verbbllm-verbb-de89b60a69ab4f37

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
consulllm-consul-4306230a577a290d

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
clamavllm-clamav-b18e31e1393571e7

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability

Dec 23, 2024
mavenGHSA-5j33-cvvr-w245high

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

Dec 17, 2024
redhatCVE-2024-50379Moderate

tomcat: RCE due to TOCTOU issue in JSP compilation

Dec 17, 2024

References

lists.debian.org / debian-lts-announce/2025/01/msg00009.html
security.netapp.com / advisory/ntap-20250103-0003
Third Party Advisory
openwall.com / lists/oss-security/2024/12/17/4
Mailing List
openwall.com / lists/oss-security/2024/12/18/2
Mailing List
lists.apache.org / thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r
Mailing ListVendor Advisory