- Description
- Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
- Source
- security@apache.org
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@apache.org
- CWE-367
- Hype score
- Not currently trending
GitHub - ph0ebus/Tomcat-CVE-2024-50379-Poc: RCE through a race condition in Apache Tomcat https://t.co/03dFZEmDsm
@akaclandestine
21 Jan 2025
4413 Impressions
24 Retweets
83 Likes
41 Bookmarks
1 Reply
0 Quotes
CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution https://t.co/pyoWs8VOV5
@buaqbot
18 Jan 2025
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution https://t.co/d7iUK9dNii
@buaqbot
18 Jan 2025
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 New Writeup Alert! 🚨 "CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution" by Bash Overflow is now live on IW! Check it out here: https://t.co/QIpIAIypNJ #apachevulnerability #cve202450379 #raceconditionexploit #bugbounty… https://t.co
@InfoSecComm
18 Jan 2025
679 Impressions
0 Retweets
9 Likes
4 Bookmarks
0 Replies
0 Quotes
⚠️ New CVE Real-World Alert: Apache Tomcat RCE Exploitation Detected CVE-2024-50379 allows RCE on Tomcat servers via a race condition, enabling easy exploitation. 🛡️ CVE: CVE-2024-50379 🔹 CVSS Score: 9.8 🔢 Event ID: 312 💻 Role: Incident Responder 🌀 Difficulty: Hard https
@LetsDefendIO
11 Jan 2025
4040 Impressions
27 Retweets
101 Likes
19 Bookmarks
0 Replies
0 Quotes
[1day1line] CVE-2024-50379/CVE-2024-56337: RCE Vulnerability Due to TOCTOU in Apache Tomcat https://t.co/O32m02RHjn hello. Today's one-line issue is CVE-2024-50379/CVE-2024-56337, a race condition vulnerability that occurred in Apache Tomcat. This is a vulnerability that can… h
@hackyboiz
5 Jan 2025
2131 Impressions
11 Retweets
44 Likes
12 Bookmarks
0 Replies
0 Quotes
Tomcat-CVE-2024-50379-Poc https://t.co/pKREuLrNoz
@ngnicky
31 Dec 2024
63 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Tomcat-CVE-2024-50379 https://t.co/5Hf9XPBfYY
@kang9693na25429
31 Dec 2024
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-50379 grants RCE in Apache Tomcat First off - don't push your code to servers with case insensitive filesystems. Second off - use nanos unikernels.
@nanovms
30 Dec 2024
182 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 New PoC: Apache Tomcat file upload vuln! CVE: CVE-2024-50379/CVE-2024-56337 Risk: High Impact: Remote code execution TTPs: T1190 (Exploit Public-Facing App) Details & PoC: https://t.co/QUBS9nw37Z #infosec #cyber #security
@gothburz
30 Dec 2024
62 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Remote Code Execution Vulnerability Found in Apache Tomcat (#CVE-2024-50379) https://t.co/dgJbxGnpFn
@UndercodeNews
30 Dec 2024
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2024-50379 2 - CVE-2024-38200 3 - CVE-2024-12856 4 - CVE-2023-48788 5 - CVE-2024-7971 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
30 Dec 2024
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
2024-12-29 の人気記事はコチラでした。(自動ツイート) #Hacker_Trends ――― GitHub - ph0ebus/Tomcat-CVE-2024-50379-Poc: RCE through a race condition in Apache Tomcat https://t.co/WUhA4ytoTD https://t.co/3BS3sXgoq3
@motikan2010
30 Dec 2024
186 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Apache fixes remote code execution bypass in Tomcat web server The vulnerability fixed in the new release is tracked as CVE-2024-56337 and addresses an incomplete mitigation for CVE-2024-50379, a critical remote code execution (RCE), for which the vendor released an incomplete… h
@johndjohnson
29 Dec 2024
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-50379: Apache Tomcat - RCE HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache Tomcat" https://t.co/3AQzi5p6ju
@d4rk_c0r3
29 Dec 2024
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-50379: RCE through a race condition in Apache Tomcat PoC https://t.co/6LPYxZGQMb https://t.co/43K0sW6PRb
@cyber_advising
29 Dec 2024
13870 Impressions
63 Retweets
270 Likes
110 Bookmarks
2 Replies
0 Quotes
[Write-up] CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution https://t.co/8xx6VyHKRi
@_havij
28 Dec 2024
54 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apache Tomcat permits an RCE on case insensitive - CVE-2024-50379 https://t.co/movjY71hWQ https://t.co/kmHdKmykIu
@MartinCulligan1
27 Dec 2024
30 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Security update: Unimus is NOT effected by CVE-2024-56337 / CVE-2024-50379. More info below... https://t.co/TVff6ph4m0
@UnimusNet
27 Dec 2024
79 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2024-50379: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1... PoC https://t.co/xro6p4k6UK
@cyber_advising
27 Dec 2024
518 Impressions
0 Retweets
4 Likes
3 Bookmarks
0 Replies
0 Quotes
📢 New blog post alert! 📢 Dive deep into CVE-2024-50379, a critical vulnerability in Apache Tomcat. Learn about its impact, exploitation, and how to mitigate the risks. Check out the first comment for link to read more details. #cybersecurity #ApacheTomcat #vulnerability… htt
@AfonsoInfante
26 Dec 2024
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Deep Dive & POC of CVE-2024-50379 Exploit Tomcat Vulnerability (9.8 Severity) https://t.co/OzLVaVjJZw
@Dinosn
26 Dec 2024
15378 Impressions
50 Retweets
190 Likes
122 Bookmarks
3 Replies
2 Quotes
Tomcat CVE-2024-50379/CVE-2024-56337 PoC https://t.co/dpTzwaRYzw
@Dinosn
26 Dec 2024
4885 Impressions
19 Retweets
92 Likes
34 Bookmarks
0 Replies
0 Quotes
Analysis of Tomcat CVE-2024-50379 / CVE-2024-56337 Conditional Competition Vulnerability https://t.co/HgGH9Gbt32
@Dinosn
25 Dec 2024
3411 Impressions
1 Retweet
20 Likes
9 Bookmarks
0 Replies
0 Quotes
A flaw in the Apache Tomcat update intended to fix a previous vulnerability has introduced another significant security issue, leaving organizations exposed to RCE attacks. CVSS: 9.8 ⚠️ Critical CVE-2024-50379/CVE-2024-56337 Both vulnerabilities, exploit a race condition in… h
@cytexsmb
24 Dec 2024
550 Impressions
1 Retweet
3 Likes
1 Bookmark
0 Replies
1 Quote
⚡️CVE-2024-50379/CVE-2024-56337 : Apache Tomcat Patches Critical RCE Vulnerability 🔥Exploit : https://t.co/Qu5xKgVb55 👇Dorks: HUNTER :/product.name="Apache Tomcat" FOFA : product="Apache-Tomcat" SHODAN : product:"Apache-Tomcat" #ApacheTomcat #hunterhow #infosec #infosecurity
@wtf_brut
24 Dec 2024
2567 Impressions
13 Retweets
66 Likes
44 Bookmarks
1 Reply
0 Quotes
Vulnerabilities CVE-2024-56337 and CVE-2024-50379 require urgent updates to protect against remote code execution. 🔧 Check versions and customize Java! More information 👉 https://t.co/1zjrkiUM4r #VPNUnlimited #CyberSecurity https://t.co/a4HvKtGn1K
@vpnunlimited
24 Dec 2024
248 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
ASF 基金会发布安全更新修复 Apache Tomcat 中的高危安全漏洞,攻击者可在服务器上远程执行代码。此漏洞是 12 月 17 日发布的 CVE-2024-50379 的不完整缓解漏洞,于是现在只能继续发补丁,并且用户需要根据自己使用的 Java 版本检查属性设置进行手动修复。查看全文:https://t.co/OQ0AYZumvr
@landiantech
24 Dec 2024
1373 Impressions
0 Retweets
6 Likes
0 Bookmarks
0 Replies
0 Quotes
Threat Alert: Apache fixes remote code execution bypass in Tomcat web server - #CVE-2024-56337 CVE-2024-56337 CVE-2024-50379 Severity: ⚠️ Critical Maturity: 🧨 Trending Learn more: https://t.co/FGpkg1Azj3 #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
24 Dec 2024
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#exploit 1. CVE-2024-50379: Apache Tomcat RCE https://t.co/WAsPq9YMAW 2. CVE-2024-48990: Qualys needrestart <3.8 - Uncontrolled Search Path Element https://t.co/TrNdynfKau
@ksg93rd
23 Dec 2024
224 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
[1/5] 🚨 Incomplete fix alert! A critical Apache Tomcat race-condition RCE vulnerability, CVE-2024-50379, has recently been found. This CVE allows attackers to upload malicious JSP files to a Tomcat server and run arbitrary code. A few days after the publication of this CVE, it…
@JFrogSecurity
23 Dec 2024
8129 Impressions
13 Retweets
54 Likes
35 Bookmarks
2 Replies
0 Quotes
Tomcat-CVE-2024-50379-Poc 一个TOCTOU竞态条件漏洞,发生在 JSP 编译过程中。当 Apache Tomcat 的默认 servlet 被配置为允许写入(非默认配置)时,这个漏洞允许在不区分大小写的文件系统上进行远程代码执行(RCE)。 https://t.co/lOk0tmB09W
@wy88215534
23 Dec 2024
72 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apache Tomcatで重大(Critical)()な遠隔コード実行の脆弱性。CVE-2024-56337はCVE-2024-50379の修正が不完全であるもの。大文字小文字が区別されないファイルシステムで、デフォルトサーブレットが書き込み可能になっている場合に、悪性JSPのアップロードが可能。 https://t.co/ioccWwVHZn
@__kokumoto
23 Dec 2024
2469 Impressions
3 Retweets
22 Likes
6 Bookmarks
1 Reply
1 Quote
♣️CVE-2024-50379 : Apache Tomcat $versions - TOCTOU Race Condition 2 Remote Code Execution 🟢POC : https://t.co/Zc99ycQTFY
@HackingTeam777
22 Dec 2024
746 Impressions
2 Retweets
17 Likes
6 Bookmarks
0 Replies
0 Quotes
Critical updates released for Apache Tomcat to fix RCE and DoS vulnerabilities (CVE-2024-50379 & CVE-2024-54677). Users should update immediately to reduce risks. 🔒💻 #TomcatVulnerabilities #RCEAttack #DoSThreat #CybersecurityNews link: https://t.co/hKezMhhiok https://t.co/
@TweetThreatNews
19 Dec 2024
108 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet https://t.co/zAkPW2Qq0i
@wy88215534
19 Dec 2024
96 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitHub - v3153/CVE-2024-50379-POC https://t.co/blANiMZY2Z
@akaclandestine
19 Dec 2024
3881 Impressions
19 Retweets
66 Likes
26 Bookmarks
2 Replies
0 Quotes
Deep Dive & POC of CVE-2024-50379 Exploit Tomcat Vulnerability (9.8 Severity) https://t.co/wTSlxY3wbX
@kang9693na25429
19 Dec 2024
846 Impressions
3 Retweets
2 Likes
0 Bookmarks
1 Reply
1 Quote
GitHub - v3153/CVE-2024-50379-POC - https://t.co/G9xBXhHtjr
@piedpiper1616
19 Dec 2024
711 Impressions
3 Retweets
8 Likes
4 Bookmarks
0 Replies
0 Quotes
CVE-2024-50379
@kang9693na25429
19 Dec 2024
119 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-50379 , Exploit & POC , Apache Tomcat (9.8 Severity) 🚨 #cve #0day #vulnerability #zeroday https://t.co/ti6V3RSjFh
@1337_kira
18 Dec 2024
23 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet https://t.co/UUKfKZrcgH #bugbounty #infosec https://t.co/yytSOHocPR
@h4x0r_dz
18 Dec 2024
6049 Impressions
21 Retweets
101 Likes
27 Bookmarks
1 Reply
1 Quote
#Vulnerability #apacheTomcat RCE and DoS Vulnerabilities Addressed in Apache Tomcat: CVE-2024-50379 and CVE-2024-54677 https://t.co/0JB8PDv2lg
@Komodosec
18 Dec 2024
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apache Tomcat fixes CVE-2024-50379 and CVE-2024-54677 #ApacheTomcat #CVE-2024-50379 #CVE-2024-54677 https://t.co/mDBNcV8GOy
@pravin_karthik
18 Dec 2024
92 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨CVE-2024-50379: Apache Tomcat - RCE via write-enabled default servlet. 👇Dorks HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache Tomcat"
@seniyorar88
18 Dec 2024
7 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Apache Tomcat Security Alert 🚨 🔒 The Apache Software Foundation has released critical updates for Apache Tomcat: - CVE-2024-50379: Important severity, allows Remote Code Execution (RCE) on case-insensitive file systems with write-enabled default servlet. -… https://t.co/
@GHak2learn27752
18 Dec 2024
229 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Solucionadas vulnerabilidades RCE y DoS en Apache Tomcat: CVE-2024-50379 CVE-2024-54677 https://t.co/ihQyoSbRAa https://t.co/vN70vFH5iG
@elhackernet
18 Dec 2024
1732 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨CVE-2024-50379: Apache Tomcat - RCE via write-enabled default servlet. 👇Dorks HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache Tomcat" 📰https://t.co/nkglXRHcf8 #bugbounty #bugbountytips https://t.co/qTsvZXKq0J
@wtf_brut
18 Dec 2024
143 Impressions
1 Retweet
4 Likes
1 Bookmark
0 Replies
0 Quotes
🚨Alert🚨CVE-2024-50379: Apache Tomcat - RCE via write-enabled default servlet. 📊 11.9m+ Services are found on https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/Pf8A56rwao 👇Query HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache…
@HunterMapping
18 Dec 2024
23411 Impressions
100 Retweets
353 Likes
220 Bookmarks
0 Replies
3 Quotes
⚠️⚠️ RCE and DoS Vulnerabilities Addressed in Apache Tomcat: CVE-2024-50379 and CVE-2024-54677 🎯6m+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link:https://t.co/GfMvWUMWTU FOFA Query:app="APACHE-Tomcat" 🔖Refer: https://t.co/CKsPhglV5e #OSINT #FOFA
@fofabot
18 Dec 2024
2221 Impressions
7 Retweets
17 Likes
7 Bookmarks
0 Replies
1 Quote