Описание
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
A flaw was found in Apache Tomcat. A Time-of-check Time-of-use (TOCTOU) race condition exists when creating Unix domain sockets. This vulnerability allows an unauthorized local user to exploit the timing window to gain access to the Unix domain socket. This could lead to information disclosure or other unauthorized operations.
Отчет
This vulnerability in Apache Tomcat is rated Low. It involves a Time-of-check Time-of-use (TOCTOU) race condition when creating Unix domain sockets, which could allow a local attacker to gain unauthorized access to the socket. Exploitation requires local access and a specific timing window, limiting its impact to information disclosure.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | tomcat | Under investigation | ||
| Red Hat Enterprise Linux 10 | tomcat9 | Under investigation | ||
| Red Hat Enterprise Linux 6 | tomcat6 | Under investigation | ||
| Red Hat Enterprise Linux 7 | tomcat | Under investigation | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Under investigation | ||
| Red Hat Enterprise Linux 8 | tomcat | Under investigation | ||
| Red Hat Enterprise Linux 9 | tomcat | Under investigation | ||
| Red Hat JBoss Web Server 5 | tomcat | Out of support scope | ||
| Red Hat JBoss Web Server 6 | tomcat | Affected | ||
| Red Hat JBoss Web Server 7 | tomcat | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
2.5 Low
CVSS3
Связанные уязвимости
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
EPSS
2.5 Low
CVSS3