SecPod

Learn Search

Search across all Learn content

← Back to Security Research
CVE-2024-50379: Apache Tomcat Remote Code Execution Vulnerability

CVE-2024-50379: Apache Tomcat Remote Code Execution Vulnerability

Apache Tomcat, one of the most widely used open-source application servers for running Java applications, has long been trusted by organizations around the world. However, as with all widely used software, vulnerabilities can pose significant risks if not addressed promptly.

Dec 19, 2024By Chaitra Sree3 min read

Apache Tomcat, one of the most widely used open-source application servers for running Java applications, has long been trusted by organizations around the world. However, as with all widely used software, vulnerabilities can pose significant risks if not addressed promptly.

Recently, a critical Remote Code Execution (RCE) vulnerability was discovered in Apache Tomcat that could potentially allow attackers to execute arbitrary code on affected systems.

What is CVE-2024-50379?

CVE-2024-50379 vulnerability in Apache Tomcat, allowing an attacker to execute arbitrary code under certain conditions. A race condition occurs when two or more threads try to access shared data at the same time, and the outcome depends on the order in which the threads execute. If properly exploited, this can allow an attacker to manipulate the state of the application, bypass security mechanisms, and gain unauthorized access to the system.

This specific race condition affects Apache Tomcat’s handling of HTTP requests and responses, which could lead to an attacker executing code on a vulnerable server without requiring any prior authentication or user interaction.

Affected Versions

  • Apache Tomcat 9.x (all versions prior to 9.0.75)
  • Apache Tomcat 10.x (all versions prior to 10.1.7)
  • Apache Tomcat 11.x (all versions prior to 11.0.0-M7)

Severity

  • CVSS Score: 9.8 (Critical)
  • This high-severity rating indicates that attackers can exploit this vulnerability with minimal difficulty, potentially leading to complete system compromise.

Mitigation and Recommendations

  1. Upgrade Apache Tomcat: The most effective remediation is to update Apache Tomcat to a patched version. This will eliminate the vulnerability and protect against potential exploitation.
    • For Tomcat 9.x users, upgrade to version 9.0.75 or later.
    • For Tomcat 10.x users, upgrade to version 10.1.7 or later.
    • For Tomcat 11.x users, upgrade to version 11.0.0-M7 or later.
  2. Apply Security Patches: If an immediate upgrade is not feasible, check with your system administrator for any available patches or security workarounds for your Tomcat version. These might help reduce the risk until a full upgrade can be performed.
  3. Monitor Logs and Network Traffic: Continuously monitor your IT network for any unusual behavior that could indicate attempted exploitation of this vulnerability.
  4. Restrict Access: Where possible, restrict external access to your Tomcat servers by using firewalls or implementing a reverse proxy. Allow access only to trusted IP addresses or services to limit the attack surface.

SanerNow Continuous Vulnerability and Exposure Management

SecPod SanerNow CVEM is a continuous vulnerability and exposure management solution designed to automatically detect, assess, prioritize, and remediate risks across your IT network. It supports all major operating systems and over 550+ third-party applications. With SanerNow, you can test patches before deployment, roll back if needed, and fully automate the patching process.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026