CVE-2024-50379 is a critical Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Apache Tomcat (versions 11.0.0-M1 to 11.0.1, 10.1.0-M1 to 10.1.33, and 9.0.0.M1 to 9.0.97, including some EOL versions), allowing Remote Code Execution (RCE) on case-insensitive file systems when the default servlet is configured for write access. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a low attack complexity and requires no user interaction, enabling full compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, there is public exploit code available on GitHub and significant community discussion, indicating a high potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.0.98CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 10.1.0, < 10.1.34CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.2CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:* | ||
>= 10.1.0-M1, <= 10.1.33CPE match | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Dec 23, 2024Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Dec 17, 2024tomcat: RCE due to TOCTOU issue in JSP compilation
Dec 17, 2024