CVE-2024-50379

Aliases:GHSA-5j33-cvvr-w245BIT-tomcat-2024-50379RHSA-2025:0342RHSA-2025:0361RHSA-2025:1920UBUNTU-CVE-2024-50379DEBIAN-CVE-2024-50379CGA-39j7-h4qg-7wg9CGA-6jgf-pgrg-v9r9CGA-8424-wvvr-vxhxCGA-8xff-5qg2-92hfCGA-j77g-fph6-rj76CGA-mh2h-3v53-5j68CGA-mr6q-r792-mwx7CGA-px9q-jr8x-22pvCGA-wr78-hm52-x5j9CGA-xvmj-3v23-7c33
Modified
Published: 17 Dec 2024, 12:34
Last modified:03 Nov 2025, 20:45

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
44.31% HIGH
44% probability -44.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Dec 2024, 12:34
Published
Vulnerability first disclosed
03 Nov 2025, 20:45
Last Modified
Vulnerability information updated

Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

CVSS Metrics

  • v4.0CRITICALScore: 9.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 44.31% Percentile: 99%

Techniques & Countermeasures

  • CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition

    The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Affected Systems

  • apache software foundationapache tomcat

    ≥ 11.0.0-M1, ≤ 11.0.1 | ≥ 10.1.0-M1, ≤ 10.1.33 | ≥ 9.0.0.M1, ≤ 9.0.97 | ≥ 8.5.0, ≤ 8.5.100

  • apachetomcat

    ≥ 9.0.0, < 9.0.98 | ≥ 10.1.0, < 10.1.34 | ≥ 11.0.0, < 11.0.2

  • chainguardthingsboard

    < 3.9-r1

  • chainguardthingsboard-tb-js-executor

    < 3.9-r1

  • chainguardthingsboard-tb-mqtt-transport

    < 3.9-r1

  • chainguardthingsboard-tb-node

    < 3.9-r1

  • chainguardthingsboard-tb-web-ui

    < 3.9-r1

  • wolfithingsboard

    < 3.9-r1

  • wolfithingsboard-tb-js-executor

    < 3.9-r1

  • wolfithingsboard-tb-mqtt-transport

    < 3.9-r1

  • wolfithingsboard-tb-node

    < 3.9-r1

  • wolfithingsboard-tb-web-ui

    < 3.9-r1

  • debiantomcat10

    < 10.1.34-0+deb12u1 | < 10.1.34-1 | < 10.1.34-1

  • debiantomcat9

    < 9.0.43-2~deb11u11 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2

  • ubuntutomcat10

    < 10.1.16-1ubuntu0.1~esm3

  • ubuntutomcat9

    all | all | all | all

  • org.apache.tomcattomcat-catalina

    ≥ 11.0.0-M1, < 11.0.2 | ≥ 10.1.0-M1, < 10.1.34 | ≥ 9.0.0.M1, < 9.0.98 | ≥ 8.5.0, ≤ 8.5.100

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 11.0.0-M1, < 11.0.2 | ≥ 10.1.0-M1, < 10.1.34 | ≥ 9.0.0.M1, < 9.0.98 | ≥ 8.5.0, ≤ 8.5.100

  • netappbootstrap_os

    na

  • redhatjws5-tomcat

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-admin-webapps

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-docs-webapp

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-el-3.0-api

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-java-jdk11

    < 0:9.0.87-6.redhat_00006.1.el7jws

  • redhatjws5-tomcat-java-jdk8

    < 0:9.0.87-6.redhat_00006.1.el7jws

  • redhatjws5-tomcat-javadoc

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-jsp-2.3-api

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-lib

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-selinux

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-servlet-4.0-api

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws5-tomcat-webapps

    < 0:9.0.87-6.redhat_00006.1.el7jws | < 0:9.0.87-6.redhat_00006.1.el8jws | < 0:9.0.87-6.redhat_00006.1.el9jws

  • redhatjws6-tomcat

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-admin-webapps

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-docs-webapp

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-el-5.0-api

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-javadoc

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-jsp-3.1-api

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-lib

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-selinux

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-servlet-6.0-api

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatjws6-tomcat-webapps

    < 0:10.1.8-15.redhat_00022.1.el8jws | < 0:10.1.8-15.redhat_00022.1.el9jws

  • redhatpki-servlet-4.0-api

    < 1:9.0.50-1.el9_2.2

  • redhatpki-servlet-engine

    < 1:9.0.50-1.el9_2.2

References (33)