Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19635 | Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 27 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Tomcat package of OpenSUSE and derived distributions. This issue occurs due to incorrect permissions and a race condition in the %post section of the Tomcat RPM package, resulting in local privilege escalation when the Tomcat package is re-installed. | Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root |
| Title | tomcat: Escalation to root from tomcat user via %post script | tomcat packaging allows for escalation to root from tomcat user |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2025-08-26T20:18:11.916Z
Reserved: 2024-01-04T12:38:34.023Z
Link: CVE-2024-22029
Updated: 2025-01-27T17:55:51.195Z
Status : Deferred
Published: 2024-10-16T14:15:04.500
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-22029
OpenCVE Enrichment
No data.
EUVD