logo

Apache fixes remote code execution bypass in Tomcat web server

ID: 89323d15-274a-509a-bf78-eb15ba2e1b2f

STIX ID: report--89323d15-274a-509a-bf78-eb15ba2e1b2f

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-23

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Apache released patches and additional mitigation guidance for a TOCTOU remote code execution vulnerability in Tomcat (CVE-2024-50379 / CVE-2024-56337). Administrators should upgrade to the patched Tomcat versions and, for Java 8/11 (and certain Java 17 configurations), set the 'sun.io.useCanonCaches' system property to false to fully mitigate risk on case-insensitive file systems; Java 21+ is unaffected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.