CVE-2022-23181: Local privilege escalation with FileStore
Last updated 5 August 2024
Other sources
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-23181?
CVE-2022-23181 is a time of check, time of use vulnerability in Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56, and 8.5.55 to 8.5.73.
How severe is CVE-2022-23181?
CVE-2022-23181 has a severity level of high with a CVSS score of 7.0.
What is the impact of CVE-2022-23181?
CVE-2022-23181 allows a local attacker to perform actions with the user privileges that the Tomcat process is using.
Which versions of Apache Tomcat are affected by CVE-2022-23181?
Apache Tomcat versions 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56, and 8.5.55 to 8.5.73 are affected by CVE-2022-23181.
How can I fix CVE-2022-23181?
To fix CVE-2022-23181, update Apache Tomcat to version 10.1.0-M9, 10.0.15, 9.0.57, or 8.5.74 or later.