Логотип exploitDog
bind:"GHSA-5j33-cvvr-w245" OR bind:"CVE-2024-50379"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-5j33-cvvr-w245" OR bind:"CVE-2024-50379"

Количество 14

Количество 14

github логотип

GHSA-5j33-cvvr-w245

12 месяцев назад

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

CVSS3: 9.8
EPSS: Высокий
ubuntu логотип

CVE-2024-50379

12 месяцев назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

CVSS3: 9.8
EPSS: Высокий
redhat логотип

CVE-2024-50379

12 месяцев назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

CVSS3: 8.1
EPSS: Высокий
nvd логотип

CVE-2024-50379

12 месяцев назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2024-50379

12 месяцев назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during ...

CVSS3: 9.8
EPSS: Высокий
fstec логотип

BDU:2024-11286

12 месяцев назад

Уязвимость сервлета DefaultServlet сервера приложений Apache Tomcat, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2025:0394-1

10 месяцев назад

Security update for tomcat

EPSS: Низкий
rocky логотип

RLSA-2025:3683

5 месяцев назад

Moderate: tomcat security update

EPSS: Низкий
rocky логотип

RLSA-2025:3645

5 месяцев назад

Moderate: tomcat security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-3683

8 месяцев назад

ELSA-2025-3683: tomcat security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-3645

8 месяцев назад

ELSA-2025-3645: tomcat security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0058-1

10 месяцев назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0033-1

10 месяцев назад

Security update for tomcat10

EPSS: Низкий
redos логотип

ROS-20250110-12

11 месяцев назад

Множественные уязвимости tomcat

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5j33-cvvr-w245

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

CVSS3: 9.8
88%
Высокий
12 месяцев назад
ubuntu логотип
CVE-2024-50379

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

CVSS3: 9.8
88%
Высокий
12 месяцев назад
redhat логотип
CVE-2024-50379

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

CVSS3: 8.1
88%
Высокий
12 месяцев назад
nvd логотип
CVE-2024-50379

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

CVSS3: 9.8
88%
Высокий
12 месяцев назад
debian логотип
CVE-2024-50379

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during ...

CVSS3: 9.8
88%
Высокий
12 месяцев назад
fstec логотип
BDU:2024-11286

Уязвимость сервлета DefaultServlet сервера приложений Apache Tomcat, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
88%
Высокий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0394-1

Security update for tomcat

10 месяцев назад
rocky логотип
RLSA-2025:3683

Moderate: tomcat security update

5 месяцев назад
rocky логотип
RLSA-2025:3645

Moderate: tomcat security update

5 месяцев назад
oracle-oval логотип
ELSA-2025-3683

ELSA-2025-3683: tomcat security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2025-3645

ELSA-2025-3645: tomcat security update (MODERATE)

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0058-1

Security update for tomcat

10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0033-1

Security update for tomcat10

10 месяцев назад
redos логотип
ROS-20250110-12

Множественные уязвимости tomcat

CVSS3: 9.8
11 месяцев назад

Уязвимостей на страницу