PT-2024-9810 · Apache+8 · Apache Tomcat+8
Nacl
+3
·
Published
2024-12-09
·
Updated
2026-05-29
·
CVE-2024-56337
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache Tomcat versions 9.0.0-M1 through 11.0.1
Description:
The issue is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that can be exploited to bypass case sensitivity checks and execute arbitrary code. This can be done by uploading a file that can be turned into malicious JSP code, resulting in remote code execution. The exploit can be carried out on case-insensitive file systems where Tomcat's default servlet has write functionality enabled. Over 894,000 Apache Tomcat applications are potentially vulnerable to this exploit. A proof-of-concept has been released, and it is expected that more exploitation will occur.
Recommendations:
Update to patched versions of Apache Tomcat and adjust Java configuration accordingly to prevent remote code execution.
As a temporary workaround, consider disabling the default servlet's write functionality on case-insensitive file systems to minimize the risk of exploitation.
Restrict access to the vulnerable
jsp files to prevent malicious code execution until the issue is resolved.Fix
RCE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Tomcat
Centos
Confluence
Red Hat
Red Os
Rocky Linux
Suse