CVE-2024-50379Time-of-check Time-of-use (TOCTOU) Race Condition in Apache Tomcat

Severity
9.8CRITICALNVD
EPSS
86.5%
top 0.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateAug 20

Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions m

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/tomcat9.0.09.0.98+2
CVEListV5apache_software_foundation/apache_tomcat11.0.0-M111.0.1+3

🔴Vulnerability Details

5
GHSA
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2024-12-20
OSV
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2024-12-17
OSV
CVE-2024-50379: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file system2024-12-17
CVEList
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation2024-12-17
GHSA
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2024-12-17

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition during JSP Compilation (CVE-2024-50379)2025-01-27

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2025-08-20
Red Hat
tomcat: RCE due to TOCTOU issue in JSP compilation2024-12-17
Debian
CVE-2024-50379: tomcat10 - Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compi...2024
Apache
Apache tomcat: CVE-2024-50379

💬Community

1
HackerOne
[SECURITY] CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet2025-05-27
CVE-2024-50379 — Apache Tomcat vulnerability | cvebase