Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade tomcat-jsp-2_3-apiUpgrade tomcat-libUpgrade tomcat-embedUpgrade tomcat10-embedUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-el-3_0-apiUpgrade tomcat10-servlet-6_0-apiUpgrade tomcat10-el-5_0-apiUpgrade tomcat10-webappsUpgrade tomcat-webappsUpgrade tomcat10-docs-webappUpgrade tomcat-jsvcUpgrade tomcat-admin-webappsUpgrade tomcat10-jsp-3_1-apiUpgrade tomcat-docs-webappUpgrade tomcat10-jsvcUpgrade tomcat10-docUpgrade tomcatUpgrade tomcat10Upgrade tomcat10-libUpgrade tomcat10-admin-webappsUpgrade tomcat-javadoc | Feb 15, 2024 | Feb 14, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub