tomcat-embed-core is vulnerable to Race Condition (TOCTOU)
53
Medium Risk
tomcat-embed-core has a time-of-check time-of-use race when creating a Unix domain socket. An unauthorized local user can open the socket during the window between permission setup and use. That exposes the Tomcat connector to a local process that should not have it. The fix creates the socket so another local user cannot open it.
You are affected if you are using a version that falls within the vulnerable range and Tomcat creates a Unix domain socket.
tomcat-embed-core is vulnerable to Race Condition (TOCTOU) in versions 9.0.42 - 9.0.120, 10.1.0 - 10.1.57 and 11.0.0 - 11.0.24.
Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.