Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-22029— tomcat packaging allows for escalation to root from tomcat user

Quick assessment

Affected
SUSE Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SUSE Linux Enterprise Server是德国SUSE公司的一套企业服务器版Linux操作系统。 SUSE Linux Enterprise Server存在安全漏洞,该漏洞源于攻击者可以通过Tomcat User Post Script绕过限制,从而提升权限。

CVSS 7.8 · High EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-22029

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
tomcat packaging allows for escalation to root from tomcat user
Source: CVE Program / CVE List V5
Vulnerability Description
Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5
Vulnerability Title
SUSE Linux Enterprise Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SUSE Linux Enterprise Server是德国SUSE公司的一套企业服务器版Linux操作系统。 SUSE Linux Enterprise Server存在安全漏洞,该漏洞源于攻击者可以通过Tomcat User Post Script绕过限制,从而提升权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Enterprise Storage 7.1 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Module for Web and Scripting 15 SP5 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server 15 SP5 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP5 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise High Performance Computing 15 SP6 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Module for Web and Scripting 15 SP6 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server 15 SP6 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP6 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server 15 SP2-LTSS ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server 15 SP3-LTSS ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server 15 SP4-LTSS ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP2 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP3 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP4 ? ~ 9.0.85-150200.57.1 -
SUSE SUSE Manager Server 4.3 ? ~ 9.0.85-150200.57.1 -
SUSE openSUSE Leap 15.5 ? ~ 9.0.85-150200.57.1 -
SUSE openSUSE Tumbleweed ? ~ 9.0.85-3.1 -

II. Public POCs for CVE-2024-22029

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-22029

请登录查看更多情报信息。

Vendor Advisories for CVE-2024-22029 (1)

Same Patch Batch · SUSE · 2024-10-16 · 15 CVEs total

CVE-2023-32191 9.9 CRITICAL rke's credentials are stored in the RKE1 Cluster state ConfigMap
CVE-2023-22650 8.8 HIGH Rancher does not automatically clean up a user deleted or disabled from the configured Aut
CVE-2023-22649 8.4 HIGH Rancher 'Audit Log' leaks sensitive information
CVE-2023-32193 8.3 HIGH Norman API Cross-site Scripting Vulnerability
CVE-2023-32192 8.3 HIGH Rancher API Server Cross-site Scripting Vulnerability
CVE-2024-22030 8.0 HIGH Rancher agents can be hijacked by taking over the Rancher Server URL
CVE-2023-32194 7.2 HIGH Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespac
CVE-2023-32196 6.6 MEDIUM Rancher's External RoleTemplates can lead to privilege escalation
CVE-2024-22032 6.5 MEDIUM Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec
CVE-2024-22033 6.3 MEDIUM obs-service-download_url is vulnerable to argument injection
CVE-2023-32189 5.9 MEDIUM Insecure handling SSH key in SUSE Manager when bootstrapping new clients
CVE-2024-22034 5.5 MEDIUM Crafted projects can overwrite special files in the .osc config directory
CVE-2023-32190 mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable
CVE-2023-32188 JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

IV. Related Vulnerabilities

V. Comments for CVE-2024-22029

No comments yet


Leave a comment