Apache TomcatÎļþ°üÂÞ©¶´[CVE-2020-1938] ¶«É­Æ½Ì¨Ìṩ½â¾ö·½°¸

Ðû²¼Ê±¼ä 2020-02-21

2ÔÂ20ÈÕ £¬¹ú¼ÒÐÅÏ¢Äþ¾²Â©¶´¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼¹ØÓÚApache TomcatµÄÄþ¾²Í¨¸æ¡£Apache TomcatÎļþ°üÂÞ©¶´£¨CNVD-2020-10487 £¬¶ÔÓ¦CVE-2020-1938£©¡£Tomcat AJPЭÒéÓÉÓÚ´æÔÚʵÏÖȱÏݵ¼ÖÂÏà¹Ø²ÎÊý¿É¿Ø £¬¹¥»÷ÕßÀûÓøÃ©¶´¿Éͨ¹ý½á¹¹Ìض¨²ÎÊý £¬¶ÁÈ¡·þÎñÆ÷webappϵÄÈÎÒâÎļþ¡£Èô·þÎñÆ÷¶Ëͬʱ´æÔÚÎļþÉÏ´«¹¦Ð§ £¬¹¥»÷Õ߿ɽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëµÄÖ´ÐС£


? ©¶´ÀûÓãº


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


? ©¶´Ó°Ïì°æ±¾£º


Tomcat 6.x

Tomcat 7.x<7.0.100

Tomcat 8.x<8.5.51

Tomcat 9.x<9.0.31


¶«É­Æ½Ì¨½â¾ö·½°¸


Ò»¡¢ ½«TomcatÁ¢¼´Éý¼¶µ½9.0.31¡¢8.5.51»ò7.0.100°æ±¾½øÐÐÐÞ¸´»ò½ûÓÃAJPЭÒé¡£


¶þ¡¢ ²úÎï¼ì²âÓë·À»¤£º


1¡¢ÒѲ¿Êð¶«É­Æ½Ì¨IDS¡¢IPS¡¢WAF²úÎïµÄ¿Í»§ÇëÈ·ÈÏÈçÏÂʼþ¹æÔòÒѾ­Ï·¢²¢Ó¦Óà £¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£ºTCP_Tomcat_AJP13_ÈÎÒâÎļþ¶ÁÈ¡[CVE-2020-1938]¡£


£¨1£©ÌìãÙÈëÇÖ¼ì²âÓë¹ÜÀíϵͳ±¨¾¯½ØÍ¼£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨3£©ÌìÇåWebÓ¦ÓÃÄþ¾²Íø¹Ø±¨¾¯½ØÍ¼£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2¡¢Â©¶´É¨Ãè


¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0ÓÚ2ÔÂ21ÈÕ½ô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸Ã©¶´½øÐмì²â £¬Óû§Éý¼¶Ì쾵©ɨ²úÎï©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃè¡£6070°æ±¾Éý¼¶°üΪ607000275 £¬Éý¼¶°üÏÂÔØµØÖ·£º

/article/type/1/146.html


ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â £¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾