CVE-2024-50379

CRITICAL

Apache Tomcat < 9.0.98 - TOCTOU Race Condition

Title source: rule

Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Exploits (18)

nomisec WORKING POC 85 stars
by SleepingBag945 · poc
https://github.com/SleepingBag945/CVE-2024-50379
nomisec WORKING POC 56 stars
by ph0ebus · poc
https://github.com/ph0ebus/Tomcat-CVE-2024-50379-Poc
github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/ApacheTomcat(CVE-2024-50379).py
nomisec WORKING POC 19 stars
by iSee857 · poc
https://github.com/iSee857/CVE-2024-50379-PoC
nomisec WORKING POC 4 stars
by v3153 · poc
https://github.com/v3153/CVE-2024-50379-POC
nomisec WORKING POC 4 stars
by dragonked2 · poc
https://github.com/dragonked2/CVE-2024-50379-POC
nomisec SCANNER 2 stars
by JFOZ1010 · poc
https://github.com/JFOZ1010/Nuclei-Template-CVE-2024-50379
nomisec WORKING POC 2 stars
by pwnosec · poc
https://github.com/pwnosec/CVE-2024-50379
nomisec WRITEUP 1 stars
by yiliufeng168 · poc
https://github.com/yiliufeng168/CVE-2024-50379-POC
nomisec WORKING POC 1 stars
by dear-cell · poc
https://github.com/dear-cell/CVE-2024-50379
nomisec WORKING POC 1 stars
by gomtaengi · poc
https://github.com/gomtaengi/CVE-2024-50379-exp
nomisec WORKING POC
by thunww · poc
https://github.com/thunww/CVE-2024-50379
nomisec WORKING POC
by Yuri08loveElaina · poc
https://github.com/Yuri08loveElaina/CVE-2024-50379-POC
github WORKING POC
by manus-use · postscriptpoc
https://github.com/manus-use/cve-pocs/tree/main/Tomcat-CVE-2024-50379
nomisec WORKING POC
by dkstar11q · poc
https://github.com/dkstar11q/CVE-2024-50379-nuclei
nomisec WORKING POC
by Alchemist3dot14 · poc
https://github.com/Alchemist3dot14/CVE-2024-50379
nomisec WORKING POC
by Yuri08loveElaina · poc
https://github.com/Yuri08loveElaina/CVE-2024-50379

Scores

CVSS v3 9.8
EPSS 0.8731
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-367
Status published

Affected Products (4)

apache/tomcat < 9.0.98
netapp/bootstrap_os
org.apache.tomcat/tomcat-catalina < 11.0.2Maven
org.apache.tomcat.embed/tomcat-embed-core < 11.0.2Maven

Timeline

Published Dec 17, 2024
Tracked Since Feb 18, 2026