CVE-2024-50379

Published Dec 17, 2024

Last updated a month ago

Overview

Description
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
Source
security@apache.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@apache.org
CWE-367

Social media

Hype score
Not currently trending
  1. GitHub - ph0ebus/Tomcat-CVE-2024-50379-Poc: RCE through a race condition in Apache Tomcat https://t.co/03dFZEmDsm

    @akaclandestine

    21 Jan 2025

    4413 Impressions

    24 Retweets

    83 Likes

    41 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution https://t.co/pyoWs8VOV5

    @buaqbot

    18 Jan 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution https://t.co/d7iUK9dNii

    @buaqbot

    18 Jan 2025

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 New Writeup Alert! 🚨 "CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution" by Bash Overflow is now live on IW! Check it out here: https://t.co/QIpIAIypNJ #apachevulnerability #cve202450379 #raceconditionexploit #bugbounty… https://t.co

    @InfoSecComm

    18 Jan 2025

    679 Impressions

    0 Retweets

    9 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ New CVE Real-World Alert: Apache Tomcat RCE Exploitation Detected CVE-2024-50379 allows RCE on Tomcat servers via a race condition, enabling easy exploitation. 🛡️ CVE: CVE-2024-50379 🔹 CVSS Score: 9.8 🔢 Event ID: 312 💻 Role: Incident Responder 🌀 Difficulty: Hard https

    @LetsDefendIO

    11 Jan 2025

    4040 Impressions

    27 Retweets

    101 Likes

    19 Bookmarks

    0 Replies

    0 Quotes

  6. [1day1line] CVE-2024-50379/CVE-2024-56337: RCE Vulnerability Due to TOCTOU in Apache Tomcat https://t.co/O32m02RHjn hello. Today's one-line issue is CVE-2024-50379/CVE-2024-56337, a race condition vulnerability that occurred in Apache Tomcat. This is a vulnerability that can… h

    @hackyboiz

    5 Jan 2025

    2131 Impressions

    11 Retweets

    44 Likes

    12 Bookmarks

    0 Replies

    0 Quotes

  7. Tomcat-CVE-2024-50379-Poc https://t.co/pKREuLrNoz

    @ngnicky

    31 Dec 2024

    63 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Tomcat-CVE-2024-50379 https://t.co/5Hf9XPBfYY

    @kang9693na25429

    31 Dec 2024

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2024-50379 grants RCE in Apache Tomcat First off - don't push your code to servers with case insensitive filesystems. Second off - use nanos unikernels.

    @nanovms

    30 Dec 2024

    182 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 New PoC: Apache Tomcat file upload vuln! CVE: CVE-2024-50379/CVE-2024-56337 Risk: High Impact: Remote code execution TTPs: T1190 (Exploit Public-Facing App) Details & PoC: https://t.co/QUBS9nw37Z #infosec #cyber #security

    @gothburz

    30 Dec 2024

    62 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 Critical Remote Code Execution Vulnerability Found in Apache Tomcat (#CVE-2024-50379) https://t.co/dgJbxGnpFn

    @UndercodeNews

    30 Dec 2024

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Top 5 Trending CVEs: 1 - CVE-2024-50379 2 - CVE-2024-38200 3 - CVE-2024-12856 4 - CVE-2023-48788 5 - CVE-2024-7971 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    30 Dec 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 2024-12-29 の人気記事はコチラでした。(自動ツイート) #Hacker_Trends ――― GitHub - ph0ebus/Tomcat-CVE-2024-50379-Poc: RCE through a race condition in Apache Tomcat https://t.co/WUhA4ytoTD https://t.co/3BS3sXgoq3

    @motikan2010

    30 Dec 2024

    186 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Apache fixes remote code execution bypass in Tomcat web server The vulnerability fixed in the new release is tracked as CVE-2024-56337 and addresses an incomplete mitigation for CVE-2024-50379, a critical remote code execution (RCE), for which the vendor released an incomplete… h

    @johndjohnson

    29 Dec 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2024-50379: Apache Tomcat - RCE HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache Tomcat" https://t.co/3AQzi5p6ju

    @d4rk_c0r3

    29 Dec 2024

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2024-50379: RCE through a race condition in Apache Tomcat PoC https://t.co/6LPYxZGQMb https://t.co/43K0sW6PRb

    @cyber_advising

    29 Dec 2024

    13870 Impressions

    63 Retweets

    270 Likes

    110 Bookmarks

    2 Replies

    0 Quotes

  17. [Write-up] CVE-2024-50379: Apache Tomcat Race Condition Vulnerability Leads to Remote Code Execution https://t.co/8xx6VyHKRi

    @_havij

    28 Dec 2024

    54 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Apache Tomcat permits an RCE on case insensitive - CVE-2024-50379 https://t.co/movjY71hWQ https://t.co/kmHdKmykIu

    @MartinCulligan1

    27 Dec 2024

    30 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Security update: Unimus is NOT effected by CVE-2024-56337 / CVE-2024-50379. More info below... https://t.co/TVff6ph4m0

    @UnimusNet

    27 Dec 2024

    79 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. CVE-2024-50379: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1... PoC https://t.co/xro6p4k6UK

    @cyber_advising

    27 Dec 2024

    518 Impressions

    0 Retweets

    4 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  21. 📢 New blog post alert! 📢 Dive deep into CVE-2024-50379, a critical vulnerability in Apache Tomcat. Learn about its impact, exploitation, and how to mitigate the risks. Check out the first comment for link to read more details. #cybersecurity #ApacheTomcat #vulnerability… htt

    @AfonsoInfante

    26 Dec 2024

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. Deep Dive & POC of CVE-2024-50379 Exploit Tomcat Vulnerability (9.8 Severity) https://t.co/OzLVaVjJZw

    @Dinosn

    26 Dec 2024

    15378 Impressions

    50 Retweets

    190 Likes

    122 Bookmarks

    3 Replies

    2 Quotes

  23. Tomcat CVE-2024-50379/CVE-2024-56337 PoC https://t.co/dpTzwaRYzw

    @Dinosn

    26 Dec 2024

    4885 Impressions

    19 Retweets

    92 Likes

    34 Bookmarks

    0 Replies

    0 Quotes

  24. Analysis of Tomcat CVE-2024-50379 / CVE-2024-56337 Conditional Competition Vulnerability https://t.co/HgGH9Gbt32

    @Dinosn

    25 Dec 2024

    3411 Impressions

    1 Retweet

    20 Likes

    9 Bookmarks

    0 Replies

    0 Quotes

  25. A flaw in the Apache Tomcat update intended to fix a previous vulnerability has introduced another significant security issue, leaving organizations exposed to RCE attacks. CVSS: 9.8 ⚠️ Critical CVE-2024-50379/CVE-2024-56337 Both vulnerabilities, exploit a race condition in… h

    @cytexsmb

    24 Dec 2024

    550 Impressions

    1 Retweet

    3 Likes

    1 Bookmark

    0 Replies

    1 Quote

  26. ⚡️CVE-2024-50379/CVE-2024-56337 : Apache Tomcat Patches Critical RCE Vulnerability 🔥Exploit : https://t.co/Qu5xKgVb55 👇Dorks: HUNTER :/product.name="Apache Tomcat" FOFA : product="Apache-Tomcat" SHODAN : product:"Apache-Tomcat" #ApacheTomcat #hunterhow #infosec #infosecurity

    @wtf_brut

    24 Dec 2024

    2567 Impressions

    13 Retweets

    66 Likes

    44 Bookmarks

    1 Reply

    0 Quotes

  27. Vulnerabilities CVE-2024-56337 and CVE-2024-50379 require urgent updates to protect against remote code execution. 🔧 Check versions and customize Java! More information 👉 https://t.co/1zjrkiUM4r #VPNUnlimited #CyberSecurity https://t.co/a4HvKtGn1K

    @vpnunlimited

    24 Dec 2024

    248 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  28. ASF 基金会发布安全更新修复 Apache Tomcat 中的高危安全漏洞,攻击者可在服务器上远程执行代码。此漏洞是 12 月 17 日发布的 CVE-2024-50379 的不完整缓解漏洞,于是现在只能继续发补丁,并且用户需要根据自己使用的 Java 版本检查属性设置进行手动修复。查看全文:https://t.co/OQ0AYZumvr

    @landiantech

    24 Dec 2024

    1373 Impressions

    0 Retweets

    6 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Threat Alert: Apache fixes remote code execution bypass in Tomcat web server - #CVE-2024-56337 CVE-2024-56337 CVE-2024-50379 Severity: ⚠️ Critical Maturity: 🧨 Trending Learn more: https://t.co/FGpkg1Azj3 #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    24 Dec 2024

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. #exploit 1. CVE-2024-50379: Apache Tomcat RCE https://t.co/WAsPq9YMAW 2. CVE-2024-48990: Qualys needrestart <3.8 - Uncontrolled Search Path Element https://t.co/TrNdynfKau

    @ksg93rd

    23 Dec 2024

    224 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. [1/5] 🚨 Incomplete fix alert! A critical Apache Tomcat race-condition RCE vulnerability, CVE-2024-50379, has recently been found. This CVE allows attackers to upload malicious JSP files to a Tomcat server and run arbitrary code. A few days after the publication of this CVE, it…

    @JFrogSecurity

    23 Dec 2024

    8129 Impressions

    13 Retweets

    54 Likes

    35 Bookmarks

    2 Replies

    0 Quotes

  32. Tomcat-CVE-2024-50379-Poc 一个TOCTOU竞态条件漏洞,发生在 JSP 编译过程中。当 Apache Tomcat 的默认 servlet 被配置为允许写入(非默认配置)时,这个漏洞允许在不区分大小写的文件系统上进行远程代码执行(RCE)。 https://t.co/lOk0tmB09W

    @wy88215534

    23 Dec 2024

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Apache Tomcatで重大(Critical)()な遠隔コード実行の脆弱性。CVE-2024-56337はCVE-2024-50379の修正が不完全であるもの。大文字小文字が区別されないファイルシステムで、デフォルトサーブレットが書き込み可能になっている場合に、悪性JSPのアップロードが可能。 https://t.co/ioccWwVHZn

    @__kokumoto

    23 Dec 2024

    2469 Impressions

    3 Retweets

    22 Likes

    6 Bookmarks

    1 Reply

    1 Quote

  34. ♣️CVE-2024-50379 : Apache Tomcat $versions - TOCTOU Race Condition 2 Remote Code Execution 🟢POC : https://t.co/Zc99ycQTFY

    @HackingTeam777

    22 Dec 2024

    746 Impressions

    2 Retweets

    17 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  35. Critical updates released for Apache Tomcat to fix RCE and DoS vulnerabilities (CVE-2024-50379 & CVE-2024-54677). Users should update immediately to reduce risks. 🔒💻 #TomcatVulnerabilities #RCEAttack #DoSThreat #CybersecurityNews link: https://t.co/hKezMhhiok https://t.co/

    @TweetThreatNews

    19 Dec 2024

    108 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet https://t.co/zAkPW2Qq0i

    @wy88215534

    19 Dec 2024

    96 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. GitHub - v3153/CVE-2024-50379-POC https://t.co/blANiMZY2Z

    @akaclandestine

    19 Dec 2024

    3881 Impressions

    19 Retweets

    66 Likes

    26 Bookmarks

    2 Replies

    0 Quotes

  38. Deep Dive & POC of CVE-2024-50379 Exploit Tomcat Vulnerability (9.8 Severity) https://t.co/wTSlxY3wbX

    @kang9693na25429

    19 Dec 2024

    846 Impressions

    3 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  39. GitHub - v3153/CVE-2024-50379-POC - https://t.co/G9xBXhHtjr

    @piedpiper1616

    19 Dec 2024

    711 Impressions

    3 Retweets

    8 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  40. CVE-2024-50379

    @kang9693na25429

    19 Dec 2024

    119 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. CVE-2024-50379 , Exploit & POC , Apache Tomcat (9.8 Severity) 🚨 #cve #0day #vulnerability #zeroday https://t.co/ti6V3RSjFh

    @1337_kira

    18 Dec 2024

    23 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  42. CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet https://t.co/UUKfKZrcgH #bugbounty #infosec https://t.co/yytSOHocPR

    @h4x0r_dz

    18 Dec 2024

    6049 Impressions

    21 Retweets

    101 Likes

    27 Bookmarks

    1 Reply

    1 Quote

  43. #Vulnerability #apacheTomcat RCE and DoS Vulnerabilities Addressed in Apache Tomcat: CVE-2024-50379 and CVE-2024-54677 https://t.co/0JB8PDv2lg

    @Komodosec

    18 Dec 2024

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Apache Tomcat fixes CVE-2024-50379 and CVE-2024-54677 #ApacheTomcat #CVE-2024-50379 #CVE-2024-54677 https://t.co/mDBNcV8GOy

    @pravin_karthik

    18 Dec 2024

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 🚨CVE-2024-50379: Apache Tomcat - RCE via write-enabled default servlet. 👇Dorks HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache Tomcat"

    @seniyorar88

    18 Dec 2024

    7 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  46. 🚨 Apache Tomcat Security Alert 🚨 🔒 The Apache Software Foundation has released critical updates for Apache Tomcat: - CVE-2024-50379: Important severity, allows Remote Code Execution (RCE) on case-insensitive file systems with write-enabled default servlet. -… https://t.co/

    @GHak2learn27752

    18 Dec 2024

    229 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Solucionadas vulnerabilidades RCE y DoS en Apache Tomcat: CVE-2024-50379 CVE-2024-54677 https://t.co/ihQyoSbRAa https://t.co/vN70vFH5iG

    @elhackernet

    18 Dec 2024

    1732 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 🚨CVE-2024-50379: Apache Tomcat - RCE via write-enabled default servlet. 👇Dorks HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache Tomcat" 📰https://t.co/nkglXRHcf8 #bugbounty #bugbountytips https://t.co/qTsvZXKq0J

    @wtf_brut

    18 Dec 2024

    143 Impressions

    1 Retweet

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  49. 🚨Alert🚨CVE-2024-50379: Apache Tomcat - RCE via write-enabled default servlet. 📊 11.9m+ Services are found on https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/Pf8A56rwao 👇Query HUNTER:/product.name="Apache Tomcat" FOFA:product="APACHE-Tomcat" SHODAN:product:"Apache…

    @HunterMapping

    18 Dec 2024

    23411 Impressions

    100 Retweets

    353 Likes

    220 Bookmarks

    0 Replies

    3 Quotes

  50. ⚠️⚠️ RCE and DoS Vulnerabilities Addressed in Apache Tomcat: CVE-2024-50379 and CVE-2024-54677 🎯6m+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link:https://t.co/GfMvWUMWTU FOFA Query:app="APACHE-Tomcat" 🔖Refer: https://t.co/CKsPhglV5e #OSINT #FOFA

    @fofabot

    18 Dec 2024

    2221 Impressions

    7 Retweets

    17 Likes

    7 Bookmarks

    0 Replies

    1 Quote