Feed/CVE-2024-50379
CVE-2024-50379CRITICALCVSS 9.8

CVE-2024-50379

Published Dec 17, 2024·Updated Jun 17, 2026

NVD Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Public Exploits & PoCs20 found

PoC: CVE-2024-50379

tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp

4

PoC: CVE-2024-50379-PoC

Apache Tomcat(CVE-2024-50379)条件竞争致远程代码执行漏洞批量检测脚本

2

PoC: CVE-2024-50379-POC

This repository contains a Python script designed to exploit CVE-2024-50379, a vulnerability that allows attackers to upload a JSP shell to a vulnerable server and execute arbitrary commands remotely. This exploit is particularly useful when the /uploads directory is either unprotected or not present on the target server.

1

PoC: Tomcat-CVE-2024-50379-Poc

RCE through a race condition in Apache Tomcat

1

PoC: CVE-2024-50379

Technical analysis of Apache Tomcat CVE-2024-50379, covering root cause, exploitation conditions, detection strategies, and mitigation techniques.

PoC: CVE-2024-50379-TOCTOU

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

PoC: CVE-2024-50379-POC

Cve exploiting

PoC: CVE-2024-50379

tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp

PoC: CVE-2024-50379

tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp

PoC: CVE-2024-50379

tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp

PoC: CVE-2024-50379

tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp

PoC: CVE-2024-50379

tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp

PoC: CVE-2024-50379

ExploitDB CVE-2024-50379 a vulnerability that enables attackers to upload a JSP shell to a vulnerable server and execute commands remotely. The exploit is especially effective when the /uploads directory is either unprotected or missing on the target server.

PoC: CVE-2024-50379-exp

CVE-2024-50379-exp

PoC: CVE-2024-50379-nuclei

Testing the latset Apache Tomcat CVE-2024-50379 Vuln

PoC: CVE-2024-50379

Testing the latset Apache Tomcat CVE-2024-50379 Vuln

PoC: CVE-2024-50379-exp

CVE-2024-50379-exp

PoC: CVE-2024-50379

CVE-2024-50379利用

PoC: CVE-2024-50379

CVE-2024-50379 is a critical vulnerability affecting multiple versions of Apache Tomcat, an open source web server and servlet container widely used for deploying Java-based web applications. The vulnerability arises from a Time-of-Use (TOCTOU) race condition that occurs when compiling JavaServer Pages (JSPs).

PoC: Nuclei-Template-CVE-2024-50379

Repositorio para alojar un template de Nuclei para probar el CVE-2024-50379 (en fase de prueba)

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free