REDHAT-BUG-2332817: Race Condition
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.2 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.34 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.98
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2332817?
The severity of REDHAT-BUG-2332817 is critical due to the potential for remote code execution.
How do I fix REDHAT-BUG-2332817?
To fix REDHAT-BUG-2332817, you should upgrade Apache Tomcat to versions 11.0.2 or later, or apply the relevant patches.
Which versions of Apache Tomcat are affected by REDHAT-BUG-2332817?
Affected versions include Apache Tomcat from 11.0.0-M1 through 11.0.1, 10.1.0-M1, and 9.0.0.M1.
What type of vulnerability is REDHAT-BUG-2332817?
REDHAT-BUG-2332817 is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability.
Can REDHAT-BUG-2332817 lead to unauthorized access?
Yes, REDHAT-BUG-2332817 can lead to unauthorized access through remote code execution on vulnerable systems.