Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade tomcat10Upgrade tomcat-javadocUpgrade tomcat10-jsp-3_1-apiUpgrade tomcatUpgrade tomcat10-admin-webappsUpgrade tomcat10-jsvcUpgrade tomcat10-libUpgrade tomcat-docs-webappUpgrade tomcat10-docUpgrade tomcat-admin-webappsUpgrade tomcat-embedUpgrade tomcat10-docs-webappUpgrade tomcat-webappsUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-jsvcUpgrade tomcat10-servlet-6_0-apiUpgrade tomcat-el-3_0-apiUpgrade tomcat10-embedUpgrade tomcat-jsp-2_3-apiUpgrade tomcat10-el-5_0-apiUpgrade tomcat-libUpgrade tomcat10-webapps | Feb 15, 2024 | Feb 14, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub