¡¾Â©¶´Í¨¸æ¡¿Apache Tomcat ¾Ü¾ø·þÎñ©¶´£¨CVE-2021-41079£©
Ðû²¼Ê±¼ä 2021-09-160x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-41079 | ʱ ¼ä | 2021-09-15 |
Àà ÐÍ | DoS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
TomcatÊÇÓÉApacheÈí¼þ»ù½ð»áÏÂÊôµÄJakartaÏîÄ¿¿ª·¢µÄÒ»¸öServletÈÝÆ÷£¬ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨"text-indent:28px;line-height:150%">2021Äê9ÔÂ15ÈÕ£¬ApacheÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËTomcatÖеÄÒ»¸ö¾Ü¾ø·þÎñ©¶´£¨CVE-2021-41079£©¡£µ±Tomcat±»ÅäÖÃΪʹÓÃNIO+OpenSSL»òNIO2+OpenSSL½øÐÐTLSʱ£¬¿ÉÒÔʹÓöñÒâÊý¾Ý°ü´¥·¢ÎÞÏÞÑ»·£¬´Ó¶øµ¼Ö¾ܾø·þÎñ¡£
Ó°Ï췶Χ
Apache Tomcat 10.0.0-M1 µ½ 10.0.2
Apache Tomcat 9.0.0-M1 µ½ 9.0.43
Apache Tomcat 8.5.0 µ½ 8.5.63
0x02 ´¦Öý¨Òé
Ŀǰ¸Ã©¶´ÒѾÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¼°Ê±Éý¼¶¸üе½ÒÔϰ汾£º
Apache Tomcat 10.0.4 »ò¸ü¸ß°æ±¾
Apache Tomcat 9.0.44 »ò¸ü¸ß°æ±¾
Apache Tomcat 8.5.64 »ò¸ü¸ß°æ±¾
×¢£º¸Ã©¶´ÒÑÔÚApache Tomcat 10.0.3 °æ±¾£¨Ðû²¼Î´Í¨¹ý£©ÖÐÐÞ¸´¡£
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202109.mbox/%3Ce1079445-c7b5-c4b0-3155-85c4cfc839ea@apache.org%3E
https://tomcat.apache.org/download-10.cgi
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-09-16 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¶«Éƽ̨
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º