Severity
7.8HIGH
EPSS
0.0%
top 94.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages23 packages

CVEListV5suse/opensuse_leap_15.5?9.0.85-150200.57.1
CVEListV5suse/opensuse_tumbleweed?9.0.85-3.1
CVEListV5suse/suse_manager_server_4.3?9.0.85-150200.57.1
CVEListV5suse/suse_enterprise_storage_7.1?9.0.85-150200.57.1
CVEListV5suse/suse_linux_enterprise_server_15_sp5?9.0.85-150200.57.1

🔴Vulnerability Details

3
OSV
CVE-2024-22029: Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root2024-10-16
CVEList
tomcat packaging allows for escalation to root from tomcat user2024-10-16
GHSA
GHSA-w8vw-x82m-vg68: Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root2024-10-16

📋Vendor Advisories

2
Red Hat
tomcat: Escalation to root from tomcat user via %post script2024-02-14
Debian
CVE-2024-22029: tomcat10 - Insecure permissions in the packaging of tomcat allow local users that win a rac...2024
CVE-2024-22029 (HIGH CVSS 7.8) | Insecure permissions in the packagi | cvebase.io