PT-2024-9579 · Apache+11 · Apache Tomcat+11

·

CVE-2024-50379

·

Published

2024-03-05

·

Updated

2026-07-09

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions prior to 11.0.2, 10.1.34, or 9.0.98.
Description The Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
Recommendations
  • Upgrade Apache Tomcat to versions 11.0.2+, 10.1.34+, or 9.0.98+ to patch CVE-2024-50379 and CVE-2024.
  • Temporarily restrict write access to the default servlet if immediate update is not possible.
  • Disable the “examples” web application in Apache Tomcat to protect against the vulnerability.
  • Set the system property sun.io.useCanonCaches to false if using Java 8 or Java 11.
  • Set the system property sun.io.useCanonCaches to false if using Java 17.
  • No further configuration is required for Java 21 onwards.
  • Tomcat 11.0.3, 10.1.35, and 9.0.99 onwards will include checks that sun.io.useCanonCaches is set appropriately before allowing the default servlet to be write enabled on a case insensitive file system. Tomcat will also set sun.io.useCanonCaches to false by default where it can.

Exploit

Fix

DoS

RCE

Race Condition

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024_1134
ALSA-2024_1444
ALSA-2025:11332
ALSA-2025:11333
ALSA-2025:11335
ALSA-2025:3645
ALSA-2025:3683
ALSA-2025_11333
ALSA-2025_11335
ALSA-2025_14177
ALSA-2025_14181
ALSA-2025_16880
ALSA-2025_3645
ALSA-2025_3683
ALT-PU-2025-13307
ALT-PU-2025-1726
ALT-PU-2025-2379
ALT-PU-2025-9797
BDU:2024-11286
BIT-TOMCAT-2024-50379
BIT-TOMCAT-2024-56337
CESA-2025_3683
CVE-2024-50379
DLA-4017-1
DSA-5845-1
ELSA-2025-3645
ELSA-2025-3683
GHSA-27HP-XHWR-WR2M
GHSA-5J33-CVVR-W245
INFSA-2025_3645
INFSA-2025_3683
MGASA-2024-0394
OESA-2024-2564
OPENSUSE-SU-2025:14622-1
OPENSUSE-SU-2025:14623-1
OPENSUSE-SU-2025_0033-1
OPENSUSE-SU-2025_0058-1
RHSA-2025:0342
RHSA-2025:0361
RHSA-2025:11332
RHSA-2025:11333
RHSA-2025:11334
RHSA-2025:11335
RHSA-2025:11381
RHSA-2025:11382
RHSA-2025:1920
RHSA-2025:3645
RHSA-2025:3646
RHSA-2025:3647
RHSA-2025:3683
RHSA-2025:3684
RHSA-2025:4521
RHSA-2025_3645
RHSA-2025_3683
RLSA-2025_3645
RLSA-2025_3683
SUSE-SU-2025:0033-1
SUSE-SU-2025:0058-1
SUSE-SU-2025:0394-1
SUSE-SU-2025_0033-1
SUSE-SU-2025_0058-1
SUSE-SU-2025_0394-1
SUSE-SU-2026:1058-1
USN-7705-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Centos
Confluence
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu