BIT-tomcat-2022-23181

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2022-23181.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tomcat-2022-23181
Aliases
Published
2024-03-06T11:09:36.902Z
Modified
2025-03-24T17:31:38.612Z
Summary
[none]
Details

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone10:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone8:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone9:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.5.55
Fixed
8.5.74
Introduced
9.0.35
Fixed
9.0.57
Introduced
10.0.0-milestone10
Fixed
10.0.0
Introduced
10.0.0-milestone5
Fixed
10.0.0
Introduced
10.0.0-milestone6
Fixed
10.0.0
Introduced
10.0.0-milestone7
Fixed
10.0.0
Introduced
10.0.0-milestone8
Fixed
10.0.0
Introduced
10.0.0-milestone9
Fixed
10.0.0
Introduced
10.0.1
Fixed
10.0.15
Introduced
10.1.0-milestone1
Fixed
10.1.0
Introduced
10.1.0-milestone2
Fixed
10.1.0
Introduced
10.1.0-milestone3
Fixed
10.1.0
Introduced
10.1.0-milestone4
Fixed
10.1.0
Introduced
10.1.0-milestone5
Fixed
10.1.0
Introduced
10.1.0-milestone6
Fixed
10.1.0
Introduced
10.1.0-milestone7
Fixed
10.1.0
Introduced
10.1.0-milestone8
Fixed
10.1.0