CVE-2024-50379
CRITICALApache Tomcat < 9.0.98 - TOCTOU Race Condition
Title source: ruleDescription
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
Exploits (18)
nomisec
WORKING POC
85 stars
by SleepingBag945 · poc
https://github.com/SleepingBag945/CVE-2024-50379
github
WORKING POC
40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/ApacheTomcat(CVE-2024-50379).py
nomisec
SCANNER
2 stars
by JFOZ1010 · poc
https://github.com/JFOZ1010/Nuclei-Template-CVE-2024-50379
nomisec
WORKING POC
by Yuri08loveElaina · poc
https://github.com/Yuri08loveElaina/CVE-2024-50379-POC
github
WORKING POC
by manus-use · postscriptpoc
https://github.com/manus-use/cve-pocs/tree/main/Tomcat-CVE-2024-50379
References (5)
Scores
CVSS v3
9.8
EPSS
0.8731
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-367
Status
published
Affected Products (4)
apache/tomcat
< 9.0.98
netapp/bootstrap_os
org.apache.tomcat/tomcat-catalina
< 11.0.2Maven
org.apache.tomcat.embed/tomcat-embed-core
< 11.0.2Maven
Timeline
Published
Dec 17, 2024
Tracked Since
Feb 18, 2026