Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
The mitigation for CVE-2024-50379 was incomplete.
Users running Tomcat on a case insensitive file system with the default servlet write enabled (readonly initialisation parameter set to the non-default value of false) may need additional configuration to fully mitigate CVE-2024-50379 depending on which version of Java they are using with Tomcat: - running on Java 8 or Java 11: the system property sun.io.useCanonCaches must be explicitly set to false (it defaults to true) - running on Java 17: the system property sun.io.useCanonCaches, if set, must be set to false (it defaults to false) - running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed)
Tomcat 11.0.3, 10.1.35 and 9.0.99 onwards will include checks that sun.io.useCanonCaches is set appropriately before allowing the default servlet to be write enabled on a case insensitive file system. Tomcat will also set sun.io.useCanonCaches to false by default where it can.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tomcat-libUpgrade tomcat-webappsUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsp-2.3-api | Jul 18, 2025 | Dec 20, 2024 |
| Amazon Linux Ami 2 | — | Upgrade tomcatUpgrade tomcat-jsvcUpgrade tomcat-el-3.0-apiUpgrade tomcat-docs-webappUpgrade tomcat-libUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-webapps | Jan 27, 2025 | Dec 20, 2024 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 10.1.34Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 11.0.2Upgrade Apache Tomcat to 9.0.98 | Dec 23, 2024 | Dec 20, 2024 |
| Debian | — | Upgrade tomcat9Upgrade tomcat10 | Dec 23, 2024 | Dec 20, 2024 |
| Freebsd | — | Upgrade tomcat9Upgrade tomcat110Upgrade tomcat101 | Dec 31, 2024 | Dec 29, 2024 |
| Oracle_linux | — | Upgrade tomcat-libUpgrade tomcat9-servlet-4.0-apiUpgrade tomcat9-webappsUpgrade tomcat9Upgrade tomcat9-jsp-2.3-apiUpgrade tomcat9-el-3.0-apiUpgrade tomcatUpgrade tomcat9-docs-webappUpgrade tomcat9-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcat-el-3.0-apiUpgrade tomcat9-libUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-webappsUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4.0-api | Jul 18, 2025 | Dec 20, 2024 |
| Redhat_linux | — | Upgrade tomcat-libUpgrade tomcat9-servlet-4.0-apiUpgrade tomcatNo solution existsUpgrade tomcat-el-3.0-apiUpgrade tomcat9Upgrade tomcat9-webappsUpgrade tomcat-webappsUpgrade tomcat9-admin-webappsUpgrade tomcat9-libUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-docs-webappUpgrade tomcat9-el-3.0-apiUpgrade tomcat9-jsp-2.3-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat9-docs-webapp | Jul 9, 2025 | Dec 20, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 20, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub