Description Preview
Overview
CVE-2021-24122 is an information disclosure vulnerability affecting multiple versions of Apache Tomcat. The vulnerability occurs specifically when Tomcat is configured to serve resources from a network location using the NTFS file system. Under these conditions, attackers could potentially access JSP source code that should not be accessible. This vulnerability is classified as CWE-706 (Use of Incorrectly-Resolved Name or Reference).
The root cause lies in how Tomcat interacts with underlying APIs. The Java Runtime Environment (JRE) API File.getCanonicalPath() behaves unexpectedly due to inconsistencies in the Windows API (FindFirstFileW) in certain scenarios. This behavior can lead to path resolution issues that expose sensitive JSP source code to unauthorized users.
Remediation
To address this vulnerability, users should upgrade to the following patched versions:
- Apache Tomcat 10.0.0 or later
- Apache Tomcat 9.0.40 or later
- Apache Tomcat 8.5.60 or later
- Apache Tomcat 7.0.107 or later
If upgrading is not immediately possible, consider the following mitigations:
- Avoid serving resources from network locations using NTFS file systems
- Implement additional access controls to restrict access to JSP source files
- Configure web application firewalls or similar security controls to block potential exploit attempts
System administrators should review their Tomcat configurations to identify if they are using network-based NTFS resources and prioritize patching accordingly.
References
- Apache Tomcat Security Announcement: https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3E
- OSS Security Mailing List: http://www.openwall.com/lists/oss-security/2021/01/14/1
- Debian Security Advisory: https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html
- NetApp Security Advisory: https://security.netapp.com/advisory/ntap-20210212-0008/
- Oracle Critical Patch Update: https://www.oracle.com//security-alerts/cpujul2021.html
- Apache Tomcat Security Pages:
- Tomcat 10: https://tomcat.apache.org/security-10.html
- Tomcat 9: https://tomcat.apache.org/security-9.html
- Tomcat 8: https://tomcat.apache.org/security-8.html
- Tomcat 7: https://tomcat.apache.org/security-7.html
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing: Medium
- Health Care & Social AssistanceHealth Care & Social Assistance: Medium
- Public AdministrationPublic Administration: Medium
- Educational ServicesEducational Services: Medium
- Finance and InsuranceFinance and Insurance: Medium
- Transportation & WarehousingTransportation & Warehousing: Medium
- Retail TradeRetail Trade: Medium
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- UtilitiesUtilities: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- InformationInformation: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- MiningMining: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- ConstructionConstruction: Low
- Wholesale TradeWholesale Trade: Low

