CVE-2024-22029

EUVD-2024-19635
Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
suseCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Debian logo
Debian Releases
Debian Product
Codename
tomcat10
bookworm
10.1.34-0+deb12u2
fixed
bookworm (security)
10.1.34-0+deb12u2
fixed
forky
10.1.46-1
fixed
sid
10.1.46-1
fixed
trixie
10.1.40-1
fixed
tomcat9
bookworm
9.0.70-2
fixed
bullseye
9.0.43-2~deb11u10
fixed
bullseye (security)
9.0.107-0+deb11u1
fixed
forky
9.0.111-1
fixed
sid
9.0.111-1
fixed
trixie
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat6
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
trusty
not-affected
xenial
not-affected
tomcat7
bionic
not-affected
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
trusty
not-affected
xenial
not-affected
tomcat8
bionic
not-affected
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
xenial
not-affected
tomcat10
focal
dne
jammy
dne
mantic
ignored
noble
not-affected
oracular
not-affected
plucky
not-affected
tomcat9
bionic
not-affected
focal
not-affected
jammy
not-affected
mantic
ignored
noble
not-affected
oracular
not-affected
plucky
not-affected