Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.tomcat.embed/tomcat-embed-core
  4. ›
  5. CVE-2022-23181

CVE-2022-23181: Time-of-check Time-of-use (TOCTOU) Race Condition

January 27, 2022 (updated November 7, 2022)

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

References

  • lists.apache.org/thread/l8x62p3k19yfcb208jo4zrb83k5mfwg9
  • nvd.nist.gov/vuln/detail/CVE-2022-23181

Code Behaviors & Features

Detect and mitigate CVE-2022-23181 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 8.5.55 up to 8.5.73, all versions starting from 9.0.35 up to 9.0.56, all versions starting from 10.0.0 up to 10.1.0, all versions starting from 10.0.1 up to 10.0.14, version 10.1.0

Solution

Unfortunately, there is no solution available yet.

Impact 7 HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition

Source file

maven/org.apache.tomcat.embed/tomcat-embed-core/CVE-2022-23181.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:56 +0000.