漏洞描述 Apache Tomcat 在 JSP 编译期间存在 Time-of-check Time-of-use (TOCTOU) Race Condition 漏洞,当默认 Servlet 被启用以进行写操作时(非默认配置),在不区分大小写的文件系统上可能导致远程代码执行(RCE)。该问题影响的 Apache Tomcat 版本为:11.0.0-M1 到 11.0.1、10.1.0-M1 到 10.1.33、9.0.0.M1 到 9.0.97。
相关漏洞推荐 Apache Tomcat URL重写绕过漏洞 (CVE-2025-55752) tomcat-default-login: Apahce Tomcat Manager Default Login POC CVE-2020-13935: Apache Tomcat WebSocket Frame Payload Length Validation Denial of Service POC CVE-2007-2449: Apache Tomcat 4.x-7.x - Cross-Site Scripting CVE-2016-8735: Apache Tomcat - Remote Code Execution via JMX Ports POC CVE-2017-12615: Apache Tomcat Servers - Remote Code Execution POC CVE-2017-12617: Apache Tomcat - Remote Code Execution POC CVE-2018-11759: Apache Tomcat JK Connect <=1.2.44 - Manager Access POC CVE-2018-11784: Apache Tomcat - Open Redirect POC CVE-2019-0221: Apache Tomcat - Cross-Site Scripting POC CVE-2019-0232: Apache Tomcat `CGIServlet` enableCmdLineArguments - Remote Code Execution POC CVE-2020-9484: Apache Tomcat Remote Command Execution POC CVE-2025-24813: Apache Tomcat Path Equivalence - Remote Code Execution