Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-27hp-xhwr-wr2m] Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability #5149

Conversation

greengeko
Copy link

@greengeko greengeko commented Jan 8, 2025

Updates

  • Affected products

Comments
Here also org.apache.tomcat.embed:tomcat-embed-core should be marked as affected, catalina is one component of embed-core

The official advisory mentions CVE-2024-56337 was made to correctly fix CVE-2024-50379 so we should logically cover the same scope.
For example this commit apache/tomcat@05ddeea (taken from the GitHub advisory for CVE-2024-50379, that covers both packages) patches org/apache/catalina/webresources/DirResourceSet.java which is included into embed-core

Also, when opening a PR this message pops up about the cve score "The entered vector string contains an error and cannot populate a score."

@github-actions github-actions bot changed the base branch from main to greengeko/advisory-improvement-5149 January 8, 2025 11:59
@advisory-database advisory-database bot merged commit 70e3bbd into greengeko/advisory-improvement-5149 Jan 8, 2025
2 checks passed
@advisory-database
Copy link
Contributor

Hi @greengeko! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the greengeko-GHSA-27hp-xhwr-wr2m branch January 8, 2025 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant