Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
History

Thu, 07 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
Description Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue. Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.88888}

epss

{'score': 0.88763}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.88612}

epss

{'score': 0.88888}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.88888}

epss

{'score': 0.88612}


Tue, 01 Jul 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tomcat
Netapp
Netapp bootstrap Os
Netapp hci Compute Node
CPEs cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
Vendors & Products Apache
Apache tomcat
Netapp
Netapp bootstrap Os
Netapp hci Compute Node

Wed, 09 Apr 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:rhel_eus:8.8

Tue, 08 Apr 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:rhel_eus:9.4
Vendors & Products Redhat enterprise Linux

Thu, 27 Feb 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.2
Vendors & Products Redhat rhel Eus

Thu, 13 Feb 2025 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat jboss Enterprise Web Server
CPEs cpe:/a:redhat:jboss_enterprise_web_server:5.8
cpe:/a:redhat:jboss_enterprise_web_server:5.8::el7
cpe:/a:redhat:jboss_enterprise_web_server:5.8::el8
cpe:/a:redhat:jboss_enterprise_web_server:5.8::el9
cpe:/a:redhat:jboss_enterprise_web_server:6.0
cpe:/a:redhat:jboss_enterprise_web_server:6.0::el8
cpe:/a:redhat:jboss_enterprise_web_server:6.0::el9
Vendors & Products Redhat
Redhat jboss Enterprise Web Server
Metrics threat_severity

Important

threat_severity

Moderate


Fri, 03 Jan 2025 12:45:00 +0000

Type Values Removed Values Added
References

Thu, 19 Dec 2024 17:45:00 +0000

Type Values Removed Values Added
Description Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.08, which fixes the issue. Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Wed, 18 Dec 2024 17:45:00 +0000

Type Values Removed Values Added
References

Wed, 18 Dec 2024 02:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 17 Dec 2024 18:45:00 +0000

Type Values Removed Values Added
References

Tue, 17 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Dec 2024 12:45:00 +0000

Type Values Removed Values Added
Description Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.08, which fixes the issue.
Title Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
Weaknesses CWE-367
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-12-17T12:34:54.827Z

Updated: 2025-08-07T11:16:52.455Z

Reserved: 2024-10-23T13:31:10.241Z

Link: CVE-2024-50379

cve-icon Vulnrichment

Updated: 2025-01-03T12:04:28.838Z

cve-icon NVD

Status : Modified

Published: 2024-12-17T13:15:18.810

Modified: 2025-08-07T12:15:28.720

Link: CVE-2024-50379

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-17T12:34:54Z

Links: CVE-2024-50379 - Bugzilla