¡¾Â©¶´Í¨¸æ¡¿Apache Tomcat¾Ü¾ø·þÎñ©¶´ (CVE-2021-42340)
Ðû²¼Ê±¼ä 2021-10-150x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-42340 | ʱ ¼ä | 2021-10-14 |
Àà ÐÍ | Dos | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚÒ°ÀûÓÃ | ·ñ |
0x01 ©¶´ÏêÇé
TomcatÊÇÓÉApacheÈí¼þ»ù½ð»áÏÂÊôµÄJakartaÏîÄ¿¿ª·¢µÄÒ»¸öServletÈÝÆ÷£¬ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨"text-indent:28px;line-height:150%">2021Äê10ÔÂ14ÈÕ£¬ApacheÐû²¼Äþ¾²Í¨¸æ£¬¹ûÈ»ÁËApache TomcatÖеÄÒ»¸ö¾Ü¾ø·þÎñ©¶´£¨CVE-2021-42340£©¡£
ÓÉÓÚ63362 bugµÄÐÞ¸´µ¼ÖÂÁËÄÚ´æÐ¹Â©ÎÊÌ⣬ΪÊÕ¼¯HTTPÉý¼¶Á¬½ÓµÄÖ¸±ê¶øÒýÈëµÄ¹¤¾ßÔÚÁ¬½Ó¹Ø±ÕºóûÓÐΪWebSocketÁ¬½ÓÊÍ·Å¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬¿ÉÄÜ»áͨ¹ý OutOfMemoryError µ¼Ö¾ܾø·þÎñ¡£
Ó°Ï췶Χ
Apache Tomcat 10.1.0-M1 - 10.1.0-M5
Apache Tomcat 10.0.0-M10 - 10.0.11
Apache Tomcat 9.0.40 - 9.0.53
Apache Tomcat 8.5.60 - 8.5.71
0x02 ´¦Öý¨Òé
Ŀǰ´Ë©¶´ÒѾÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¼°Ê±Éý¼¶¸üе½ÒÔϰ汾£º
Apache Tomcat 10.1.0-M6 »ò¸ü¸ß°æ±¾
Apache Tomcat 10.0.12 »ò¸ü¸ß°æ±¾
Apache Tomcat 9.0.54 »ò¸ü¸ß°æ±¾
Apache Tomcat 8.5.72 »ò¸ü¸ß°æ±¾
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/download-10.cgi
0x03 ²Î¿¼Á´½Ó
https://tomcat.apache.org/security-10.html
http://mail-archives.apache.org/mod_mbox/www-announce/202110.mbox/%3C9b8b83e3-7fec-a26d-7780-e5d4a85f7df6@apache.org%3E
https://github.com/apache/tomcat/commit/31d62426645824bdfe076a0c0eafa904d90b4fb9
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42340
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-10-15 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¶«Éƽ̨
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º