CVE-2024-56337Time-of-check Time-of-use (TOCTOU) Race Condition in Apache Tomcat

Severity
9.8CRITICALNVD
EPSS
11.5%
top 6.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateApr 15

Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. The mitigation for CVE-2024-50379 was incomplete. Users running Tomcat on a case insensitive file system with the default

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/tomcat9.0.09.0.98+2
CVEListV5apache_software_foundation/apache_tomcat11.0.0-M111.0.1+3

🔴Vulnerability Details

4
GHSA
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2024-12-20
CVEList
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete2024-12-20
OSV
CVE-2024-56337: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat2024-12-20
OSV
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2024-12-20

📋Vendor Advisories

5
Oracle
Oracle Oracle Communications Risk Matrix: BEServer (Apache Tomcat) — CVE-2024-563372025-04-15
Oracle
Oracle Oracle Communications Risk Matrix: Configuration Management Platform (Apache Tomcat) — CVE-2024-563372025-01-15
Red Hat
tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation2024-12-20
Debian
CVE-2024-56337: tomcat10 - Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat...2024
Apache
Apache tomcat: CVE-2024-50379
CVE-2024-56337 — Apache Tomcat vulnerability | cvebase