First published: Wed Oct 16 2024(Updated: )
Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Tomcat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22029 has been rated as a high severity vulnerability due to the risk of local root escalation when exploiting insecure permissions during package installation.
To fix CVE-2024-22029, ensure that proper file permissions are set during the installation of Apache Tomcat to prevent unauthorized access by local users.
CVE-2024-22029 affects users of Apache Tomcat who install the software with insecure permissions, potentially allowing local users to exploit the vulnerability.
CVE-2024-22029 can affect all versions of Apache Tomcat that do not enforce secure permission settings during package installation.
No, CVE-2024-22029 is a local privilege escalation vulnerability and cannot be exploited remotely, as it requires local access during package installation.