CVE-2021-24122
published 2021-01-14CVE-2021-24122: When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59…
PriorityP346medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
22.85%
97.5th percentile
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 7.0.0 – 7.0.106 | — |
| apache | tomcat | 8.5.0 – 8.5.59 | — |
| apache | tomcat | 9.0.1 – 9.0.39 | — |
| apache_software_foundation | apache_tomcat | >= Apache Tomcat 10 < 10.0.0-M10 | 10.0.0-M10 |
| apache_software_foundation | apache_tomcat | >= Apache Tomcat 7 < 7.0.106 | 7.0.106 |
| apache_software_foundation | apache_tomcat | >= Apache Tomcat 8.5 < 8.5.60 | 8.5.60 |
| apache_software_foundation | apache_tomcat | >= Apache Tomcat 9 < 9.0.40 | 9.0.40 |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.40-1 (bookworm) | tomcat9 9.0.40-1 (bookworm) |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploitable only when Apache Tomcat serves resources from a network location using the NTFS file system — detection should focus on Windows hosts with Tomcat serving content over UNC/network NTFS paths ↗
- →The attack vector is HTTP and the exploit is remote; monitor HTTP responses from Tomcat for raw JSP source code leakage (e.g., responses containing '<%' tags with Java code rather than rendered output) ↗
- →Root cause is Windows API FindFirstFileW behaving inconsistently, leading File.getCanonicalPath() to return unexpected paths — on Windows, monitor for anomalous path canonicalization results in Tomcat JVM that could bypass security constraints ↗
- →Security constraints bypass is also possible, not just source disclosure — monitor for HTTP 200 responses to requests for .jsp files that should be protected by security-constraint elements in web.xml ↗
- ·Vulnerability only affects Tomcat running on Windows with resources served from a network (NTFS) location; Linux/RHEL deployments are not affected because FindFirstFileW() is Windows-native code and RHEL does not ship NTFS support ↗
- ·Affected Apache Tomcat version ranges: 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59, and 7.0.0 to 7.0.106; fixed in 9.0.40, 8.5.60, 7.0.107 ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_apache5.9MEDIUM
vendor_debian5.9LOW
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Information Disclosure in Apache Tomcat
ghsa·2021-05-13
CVE-2021-24122 [MEDIUM] CWE-200 Information Disclosure in Apache Tomcat
Information Disclosure in Apache Tomcat
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.
OSV
Information Disclosure in Apache Tomcat
osv·2021-05-13
CVE-2021-24122 [MEDIUM] Information Disclosure in Apache Tomcat
Information Disclosure in Apache Tomcat
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.
OSV
CVE-2021-24122: When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10
osv·2021-01-14·CVSS 5.9
CVE-2021-24122 [MEDIUM] CVE-2021-24122: When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Folders, Files & Attachments (Apache Tomcat) — CVE-2021-24122
vendor_oracle·2021-07-15·CVSS 5.9
CVE-2021-24122 [MEDIUM] Oracle Oracle Supply Chain Risk Matrix: Folders, Files & Attachments (Apache Tomcat) — CVE-2021-24122
Oracle Oracle Supply Chain Risk Matrix: Folders, Files & Attachments (Apache Tomcat) vulnerability
CVE: CVE-2021-24122
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
tomcat: Information disclosure when using NTFS file system
vendor_redhat·2021-01-14·CVSS 5.9
CVE-2021-24122 [MEDIUM] CWE-200 tomcat: Information disclosure when using NTFS file system
tomcat: Information disclosure when using NTFS file system
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.
A flaw was found in Apache Tomcat. When serving resources from a network location using the NTFS file system, it was possible to bypass security constraints and view the source code for JSPs in some configurations. The root cause was the unexpected behavior of the JRE API File.getCanonicalPa
Debian
CVE-2021-24122: tomcat9 - When serving resources from a network location using the NTFS file system, Apach...
vendor_debian·2021·CVSS 5.9
CVE-2021-24122 [MEDIUM] CVE-2021-24122: tomcat9 - When serving resources from a network location using the NTFS file system, Apach...
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.
Scope: local
bookworm: resolved (fixed in 9.0.40-1)
bullseye: resolved (fixed in 9.0.40-1)
forky: resolved (fixed in 9.0.40-1)
sid: resolved (fixed in 9.0.40-1)
trixie: resolved (fixed in 9.0.40-1)
Apache
Apache tomcat: CVE-2021-24122
vendor_apache·CVSS 5.9
CVE-2021-24122 [MEDIUM] Apache tomcat: CVE-2021-24122
Apache tomcat: CVE-2021-24122
When serving resources from a network location using the NTFS file system it was possible to bypass security constraints and/or view the source code for JSPs in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API ( FindFirstFileW ) in some circumstances. This was fixed with commit 920dddbd . This issue was reported the Apache Tomcat Security team by Ilja Brander on 26 October 2020. The issue was made public on 14 January 2021. Affects: 8.5.0 to 8.5.59 Moderate: HTTP/2 request header mix-up
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2021/01/14/1https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7382e1e35b9bc7c8f320b90ad77e74c13172d08034e20c18000fe710%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r776c64337495bf28b7d5597268114a888e3fad6045c40a0da0c66d4d%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r7e0bb9ea415724550e2b325e143b23e269579e54d66fcd7754bd0c20%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb32a73b7cb919d4f44a2596b6b951274c0004fc8b0e393d6829a45f9%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00018.htmlhttps://security.netapp.com/advisory/ntap-20210212-0008/https://www.oracle.com//security-alerts/cpujul2021.htmlhttp://www.openwall.com/lists/oss-security/2021/01/14/1https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7382e1e35b9bc7c8f320b90ad77e74c13172d08034e20c18000fe710%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r776c64337495bf28b7d5597268114a888e3fad6045c40a0da0c66d4d%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r7e0bb9ea415724550e2b325e143b23e269579e54d66fcd7754bd0c20%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb32a73b7cb919d4f44a2596b6b951274c0004fc8b0e393d6829a45f9%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00018.htmlhttps://security.netapp.com/advisory/ntap-20210212-0008/https://www.oracle.com//security-alerts/cpujul2021.html
2021-01-14
Published