CVE-2024-56337 is a critical Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability affecting Apache Tomcat versions 11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, and 9.0.0.M1 through 9.0.97, as well as older EOL versions. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While not yet in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.0.98CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 10.1.0, < 10.1.34CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.2CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:* | ||
>= 10.1.0-M1, <= 10.1.33CPE match | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.