Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

CVE-2024-50379: Apache Tomcat allows attackers to execute malicious code on case insensitive file systems

Exploitation likelihood: 44%
GHSA-5j33-cvvr-w245 CVE-2024-50379 CVE-2024-50379
Summary

Apache Tomcat versions 11.0.0-M1 to 11.0.1, 10.1.0-M1 to 10.1.33, 9.0.0.M1 to 9.0.97, and 8.5.0 to 8.5.100 are affected. If you have a non-standard configuration and your file system is not case sensitive, an attacker could potentially inject malicious code and execute it. To fix this issue, update to version 11.0.2, 10.1.34 or 9.0.98.

What to do
  • Update apache org.apache.tomcat:tomcat-catalina to version 11.0.2.
  • Update apache org.apache.tomcat:tomcat-catalina to version 10.1.34.
  • Update apache org.apache.tomcat:tomcat-catalina to version 9.0.98.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 11.0.2.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 10.1.34.
  • Update apache org.apache.tomcat.embed:tomcat-embed-core to version 9.0.98.
Affected software
Ecosystem VendorProductAffected versions
maven apache org.apache.tomcat:tomcat-catalina >= 11.0.0-M1, < 11.0.2
>= 10.1.0-M1, < 10.1.34
>= 9.0.0.M1, < 9.0.98
>= 8.5.0, <= 8.5.100
Fix: upgrade to 11.0.2
maven apache org.apache.tomcat.embed:tomcat-embed-core >= 11.0.0-M1, < 11.0.2
>= 10.1.0-M1, < 10.1.34
>= 9.0.0.M1, < 9.0.98
>= 8.5.0, <= 8.5.100
Fix: upgrade to 11.0.2
apache tomcat >= 9.0.0, < 9.0.98
>= 10.1.0, < 10.1.34
>= 11.0.0, < 11.0.2
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
netapp bootstrap_os All versions
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
Original title
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write...
Original description
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.

The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.

Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
ghsa CVSS3.1 9.8
ghsa CVSS4.0 7.2
Vulnerability type
CWE-367
Published: 17 Dec 2024 · Updated: 12 Jul 2026 · First seen: 6 Mar 2026