Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
The mitigation for CVE-2024-50379 was incomplete.
Users running Tomcat on a case insensitive file system with the default servlet write enabled (readonly initialisation parameter set to the non-default value of false) may need additional configuration to fully mitigate CVE-2024-50379 depending on which version of Java they are using with Tomcat: - running on Java 8 or Java 11: the system property sun.io.useCanonCaches must be explicitly set to false (it defaults to true) - running on Java 17: the system property sun.io.useCanonCaches, if set, must be set to false (it defaults to false) - running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed)
Tomcat 11.0.3, 10.1.35 and 9.0.99 onwards will include checks that sun.io.useCanonCaches is set appropriately before allowing the default servlet to be write enabled on a case insensitive file system. Tomcat will also set sun.io.useCanonCaches to false by default where it can.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tomcatUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-docs-webappUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcat-libUpgrade tomcat-webapps | Jul 18, 2025 | Dec 20, 2024 |
| Amazon Linux Ami 2 | — | Upgrade tomcatUpgrade tomcat-jsvcUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcat-el-3.0-apiUpgrade tomcat-webapps | Jan 27, 2025 | Dec 20, 2024 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 11.0.2Upgrade Apache Tomcat to 9.0.98Upgrade Apache Tomcat to 10.1.34Upgrade Apache Tomcat to the latest available version | Dec 23, 2024 | Dec 20, 2024 |
| Debian | — | Upgrade tomcat10Upgrade tomcat9 | Dec 23, 2024 | Dec 20, 2024 |
| Freebsd | — | Upgrade tomcat101Upgrade tomcat9Upgrade tomcat110 | Dec 31, 2024 | Dec 29, 2024 |
| Oracle_linux | — | Upgrade tomcat9-servlet-4.0-apiUpgrade tomcat-libUpgrade tomcat9Upgrade tomcat9-jsp-2.3-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-webappsUpgrade tomcat9-docs-webappUpgrade tomcat9-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcat9-libUpgrade tomcat9-el-3.0-apiUpgrade tomcatUpgrade tomcat9-webapps | Jul 18, 2025 | Dec 20, 2024 |
| Redhat_linux | — | Upgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat9-servlet-4.0-apiUpgrade tomcat9Upgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat9-webappsNo solution existsUpgrade tomcat9-admin-webappsUpgrade tomcat9-el-3.0-apiUpgrade tomcat9-libUpgrade tomcat9-jsp-2.3-apiUpgrade tomcat-docs-webappUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webappsUpgrade tomcat9-docs-webappUpgrade tomcat-servlet-4.0-api | Jul 9, 2025 | Dec 20, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 20, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub