google339
microsoft285
facebook234
exploit220
malware169
rce167
apple160
bug-bounty148
cve147
xss104
browser85
phishing75
supply-chain69
writeup69
privilege-escalation61
dos59
account-takeover56
react54
reverse-engineering49
aws48
docker48
ctf47
node47
cloudflare46
cloud44
pentest42
open-source39
auth-bypass37
info-disclosure36
oauth36
lfi35
ai-agents31
race-condition28
buffer-overflow28
postmessage27
ssrf24
sqli23
kubernetes22
wordpress21
cache-poisoning19
machine-learning19
csrf18
automation18
websocket18
llm17
mobile17
code-generation16
tool16
idor16
osint15
0
7/10
CVE-2024-50379 is a critical TOCTOU race condition vulnerability in Apache Tomcat (CVSS 9.8) affecting JSP compilation that allows remote code execution on case-insensitive filesystems when the default servlet is misconfigured with write permissions. The article provides a complete POC demonstrating how attackers can upload a benign JSP file then overwrite it with malicious code using case-sensitivity tricks (file.jsp vs FILE.JSP on Windows).
cve-2024-50379
tomcat
race-condition
toctou
rce
jsp
file-upload
arbitrary-code-execution
windows
case-insensitive-filesystem
web-server
misconfiguration
CVE-2024-50379
Apache Tomcat
Vidhi Patel
OpenWall