¡¾Â©¶´Í¨¸æ¡¿Apache TomcatÔ¶³Ì´úÂëÖ´ÐЩ¶´(CVE-2025-24813)
Ðû²¼Ê±¼ä 2025-03-11Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Apache TomcatÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ||
CVE ID | CVE-2025-24813 | ||
©¶´ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖʱ¼ä | 2025-03-11 |
©¶´ÆÀ·Ö | 7.5 | ©¶´Æ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬Ö÷ÒªÓÃÓÚÔËÐÐJavaÓ¦Ó÷¨Ê½£¬ÌرðÊÇ»ùÓÚServletºÍJavaServer Pages¼¼ÊõµÄÓ¦Óá£ËüÓÉApacheÈí¼þ»ù½ð»á¿ª·¢£¬¹ã·ºÓ¦ÓÃÓÚWeb¿ª·¢ºÍÆóÒµ¼¶Ó¦Ó÷¨Ê½ÖУ¬Ö§³ÖServlet¡¢JavaServer PagesÒÔ¼°WebSocketµÈ¼¼Êõ£¬¾ßÓиßÐÔÄÜ¡¢¿ÉÀ©Õ¹ÐԺͿɿ¿ÐÔ¡£
2025Äê3ÔÂ11ÈÕ£¬¶«Éƽ̨VSRC¼à²âµ½ApacheÐû²¼ÁËCVE-2025-24813Äþ¾²Í¨¸æ£¬Ö¸³öApache Tomcat´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£¸Ã©¶´¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС¢ÐÅϢй¶»òÊý¾Ý¸Ä¶¯¡£¹¥»÷ÕßÔÚÌØ¶¨Ìõ¼þÏ£¨ÈçĬÈÏServletдȨÏÞ¿ªÆô¡¢ÆôÓò¿ÃÅPUTÇëÇ󣩿ÉÉÏ´«Îļþ·ÃÎÊÄþ¾²Ãô¸ÐÄÚÈÝ»ò´¥·¢Ô¶³Ì´úÂëÖ´ÐС£¸Ã©¶´CVSSv3ÆÀ·Ö7.5£¬Â©¶´Æ·¼¶Îª¸ßΣ¡£
¶þ¡¢Ó°Ï췶Χ
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://tomcat.apache.org/