tomcat

1 article
sort: new top best
clear filter
0 7/10

CVE-2024-50379 is a critical TOCTOU race condition vulnerability in Apache Tomcat (CVSS 9.8) affecting JSP compilation that allows remote code execution on case-insensitive filesystems when the default servlet is misconfigured with write permissions. The article provides a complete POC demonstrating how attackers can upload a benign JSP file then overwrite it with malicious code using case-sensitivity tricks (file.jsp vs FILE.JSP on Windows).

CVE-2024-50379 Apache Tomcat Vidhi Patel OpenWall
infosecwriteups.com · Vidhi patel · 4 hours ago · details