Apache Tomcat Vulnerability CVE-2024-56337 Exposes Servers to RCE Attacks

Share:

The Apache Software Foundation (ASF) has released a security update to address an important vulnerability in its Tomcat server software that could result in remote code execution (RCE) under certain conditions.

The vulnerability, tracked as CVE-2024-56337, has been described as an incomplete mitigation for CVE-2024-50379 (CVSS score: 9.8), another critical security flaw in the same product that was previously addressed on December 17, 2024.

“Users running Tomcat on a case insensitive file system with the default servlet write enabled (readonly initialisation parameter set to the non-default value of false) may need additional configuration to fully mitigate CVE-2024-50379 depending on which version of Java they are using with Tomcat,” the project maintainers said in an advisory last week.

Both the flaws are Time-of-check Time-of-use (TOCTOU) race condition vulnerabilities that could result in code execution on case-insensitive file systems when the default servlet is enabled for write.

“Concurrent read and upload under load of the same file can bypass Tomcat’s case sensitivity checks and cause an uploaded file to be treated as a JSP leading to remote code execution,” Apache noted in an alert for CVE-2024-50379.

CVE-2024-56337 impacts the below versions of Apache Tomcat –

  • Apache Tomcat 11.0.0-M1 to 11.0.1 (Fixed in 11.0.2 or later)
  • Apache Tomcat 10.1.0-M1 to 10.1.33 (Fixed in 10.1.34 or later)
  • Apache Tomcat 9.0.0.M1 to 9.0.97 (Fixed in 9.0.98 or later)

Additionally, users are required to carry out the following configuration changes depending on the version of Java being run –

  • Java 8 or Java 11 – Explicitly set system property sun.io.useCanonCaches to false (it defaults to true)
  • Java 17 – Set system property sun.io.useCanonCaches to false, if already set (it defaults to false)
  • Java 21 and later – No action is required, as the system property has been removed

The ASF credited security researchers Nacl, WHOAMI, Yemoli, and Ruozhi for identifying and reporting both shortcomings. It also acknowledged the KnownSec 404 Team for independently reporting CVE-2024-56337 with a proof-of-concept (PoC) code.

The disclosure comes as the Zero Day Initiative (ZDI) shared details of a critical bug in Webmin (CVE-2024-12828, CVSS score: 9.9) that allows authenticated remote attackers to execute arbitrary code.

“The specific flaw exists within the handling of CGI requests,” the ZDI said. “The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.”

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
7:02 am, Jun 10, 2025
weather icon 15°C
L: 14° | H: 16°
broken clouds
Humidity: 81 %
Pressure: 1015 mb
Wind: 14 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
14° | 16°°C 0.39 mm 39% 11 mph 82 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 23°°C 0 mm 0% 12 mph 82 % 1021 mb 0 mm/h
Thu Jun 12 10:00 pm
weather icon
15° | 24°°C 0.2 mm 20% 11 mph 79 % 1017 mb 0 mm/h
Fri Jun 13 10:00 pm
weather icon
17° | 30°°C 1 mm 100% 12 mph 91 % 1018 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 11 mph 97 % 1020 mb 0 mm/h
Today 7:00 am
weather icon
15° | 15°°C 0 mm 0% 10 mph 81 % 1015 mb 0 mm/h
Today 10:00 am
weather icon
16° | 17°°C 0 mm 0% 11 mph 82 % 1015 mb 0 mm/h
Today 1:00 pm
weather icon
18° | 20°°C 0.39 mm 39% 11 mph 70 % 1016 mb 0 mm/h
Today 4:00 pm
weather icon
22° | 22°°C 0.2 mm 20% 10 mph 52 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
20° | 20°°C 0 mm 0% 6 mph 46 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 4 mph 61 % 1020 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 14°°C 0 mm 0% 4 mph 78 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 13°°C 0 mm 0% 3 mph 82 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€95,708.03
3.68%
Ethereum(ETH)
€2,336.35
7.44%
Tether(USDT)
€0.88
-0.01%
XRP(XRP)
€2.00
2.22%
Solana(SOL)
€138.37
5.31%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.167312
5.54%
Shiba Inu(SHIB)
€0.000011
4.18%
Pepe(PEPE)
€0.000011
9.12%
Peanut the Squirrel(PNUT)
€0.248638
11.15%
Scroll to Top