Apache Tomcat maintainers disclosed and patched CVE-2024-50379, a critical remote code execution flaw tied to the default servlet when write access is enabled. The bug is a TOCTOU race condition during JSP compilation that can let an unauthenticated attacker upload specially crafted files and execute code on vulnerable servers under specific conditions. The issue affects Tomcat 11.0.x before 11.0.2, 10.1.x before 10.1.34, and 9.0.x before 9.0.98.
Advisories also addressed CVE-2024-54677, a separate denial-of-service issue in Tomcat sample web applications caused by unrestricted total upload size. Defenders were urged to upgrade immediately to 11.0.2, 10.1.34, or 9.0.98, and to review deployments that expose write-enabled default servlet functionality or retain sample applications in production.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
An Apache security notice disclosed CVE-2024-50379 affecting Apache Tomcat, describing an RCE issue involving the write-enabled default servlet.
Apache Tomcat developers released security updates addressing the critical CVE-2024-50379 and CVE-2024-54677. The fixes were issued in Tomcat 11.0.2, 10.1.34, and 9.0.98, with guidance to upgrade immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.