[GHSA-27hp-xhwr-wr2m] Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability #5149
+59
−5
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates
Comments
Here also org.apache.tomcat.embed:tomcat-embed-core should be marked as affected, catalina is one component of embed-core
The official advisory mentions CVE-2024-56337 was made to correctly fix CVE-2024-50379 so we should logically cover the same scope.
For example this commit apache/tomcat@05ddeea (taken from the GitHub advisory for CVE-2024-50379, that covers both packages) patches org/apache/catalina/webresources/DirResourceSet.java which is included into embed-core
Also, when opening a PR this message pops up about the cve score "The entered vector string contains an error and cannot populate a score."