Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
CVE-2024-50379: Apache Tomcat allows attackers to execute malicious code on case insensitive file systems
Exploitation likelihood: 44%
GHSA-5j33-cvvr-w245
CVE-2024-50379
CVE-2024-50379
Summary
Apache Tomcat versions 11.0.0-M1 to 11.0.1, 10.1.0-M1 to 10.1.33, 9.0.0.M1 to 9.0.97, and 8.5.0 to 8.5.100 are affected. If you have a non-standard configuration and your file system is not case sensitive, an attacker could potentially inject malicious code and execute it. To fix this issue, update to version 11.0.2, 10.1.34 or 9.0.98.
What to do
- Update apache org.apache.tomcat:tomcat-catalina to version 11.0.2.
- Update apache org.apache.tomcat:tomcat-catalina to version 10.1.34.
- Update apache org.apache.tomcat:tomcat-catalina to version 9.0.98.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.2.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.34.
- Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.98.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | apache | org.apache.tomcat:tomcat-catalina |
>= 11.0.0-M1, < 11.0.2 >= 10.1.0-M1, < 10.1.34 >= 9.0.0.M1, < 9.0.98 >= 8.5.0, <= 8.5.100 Fix: upgrade to 11.0.2
|
| maven | apache | org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.2 >= 10.1.0-M1, < 10.1.34 >= 9.0.0.M1, < 9.0.98 >= 8.5.0, <= 8.5.100 Fix: upgrade to 11.0.2
|
| – | apache | tomcat |
>= 9.0.0, < 9.0.98 >= 10.1.0, < 10.1.34 >= 11.0.0, < 11.0.2 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| – | netapp | bootstrap_os |
All versions
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:* |
Original title
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write...
Original description
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
ghsa CVSS3.1
9.8
ghsa CVSS4.0
7.2
Vulnerability type
CWE-367
- https://nvd.nist.gov/vuln/detail/CVE-2024-50379
- https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r
- https://github.com/apache/tomcat/commit/05ddeeaa54df1e2dc427d0164bedd6b79f78d81f
- https://github.com/apache/tomcat/commit/43b507ebac9d268b1ea3d908e296cc6e46795c00
- https://github.com/apache/tomcat/commit/631500b0c9b2a2a2abb707e3de2e10a5936e5d41
- https://github.com/apache/tomcat/commit/684247ae85fa633b9197b32391de59fc54703842
- https://github.com/apache/tomcat/commit/8554f6b1722b33a2ce8b0a3fad37825f3a75f2d2
- https://github.com/apache/tomcat/commit/cc7a98b57c6dc1df21979fcff94a36e068f4456c
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.34
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.2
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.98
- http://www.openwall.com/lists/oss-security/2024/12/17/4
- http://www.openwall.com/lists/oss-security/2024/12/18/2
- https://security.netapp.com/advisory/ntap-20250103-0003
- https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html
- https://github.com/advisories/GHSA-5j33-cvvr-w245
- https://security.netapp.com/advisory/ntap-20250103-0003/ Third Party Advisory
Published: 17 Dec 2024 · Updated: 12 Jul 2026 · First seen: 6 Mar 2026