¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©·ì϶

°ä²¼¹¦·ò 2025-03-11

Apache TomcatÊdzÛÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬£¬£¬£¬£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÀûÓ÷¨Ê½£¬£¬£¬£¬£¬¿í·ºÓÃÓÚÆóÒµ¼¶WebÀûÓᣡ£¡£¡£¡£


2025Äê3ÔÂ11ÈÕ£¬£¬£¬£¬£¬Tomcat¹Ù·½°ä²¼ÁËÒ»¸ö°²È«²¼¸æ£¬£¬£¬£¬£¬½¨¸´Ò»¸öÌØ¶¨Ç°ÌáµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-24813£©¡£¡£¡£¡£¡£¸Ã·ì϶¿Éµ¼Ö·ÇĬÈÏÅäÖõÄTomcat±»¹¥»÷ÕßÀûÓ㬣¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´´Ë·ì϶¡£¡£¡£¡£¡£

Ó°Ïì°æ±¾


version < Apache Tomcat 11.0.3
version < Apache Tomcat 10.1.35

version < Apache Tomcat 9.0.99


·ì϶³ÉÒò


¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇé¿öÏ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚÌØ¶¨Ä¿Â¼ÏÂдÈëËÁÒâÎļþÃûµÄÎļþ£¬£¬£¬£¬£¬½áºÏTomcatµÄsessionÎļþ´æ´¢Ö°ÄÜ£¬£¬£¬£¬£¬Äܹ»ÊµÏÖ·´ÐòÁл¯RCE¡£¡£¡£¡£¡£¸Ã·ì϶ÀûÓñØÒªÂú×ãÒÔϼ¸¸öǰÌ᣺



£¨1£©Ä¬ÈÏservlet¿ªÆôдÈë²Ù×÷¡£¡£¡£¡£¡£
£¨2£©Ê¹ÓûùÓÚÎļþ´æ´¢µÄsession£¬£¬£¬£¬£¬ÇÒ´æ´¢õ辶ĬÈÏ¡£¡£¡£¡£¡£

£¨3£©´æÔÚ·´ÐòÁл¯ÀûÓÃÁ´µÄjar°ü¡£¡£¡£¡£¡£


·ì϶¸´ÏÖ


ͼƬ1.png


½¨¸´½¨Òé


Apache¹Ù·½ÒѰ䲼°²È«¹«¸æ²¢°ä²¼Á˽¨¸´°æ±¾£¬£¬£¬£¬£¬Ç뾡¿ìÏÂÔØ°²È«°æ±¾½¨¸´·ì϶£º


? Apache Tomcat 11.0.3 or later
Apache Tomcat 10.1.35 or later

Apache Tomcat 9.0.99 or later


¹¦·òÏß


2025Äê3ÔÂ11ÈÕ ³§Ḛ́䲼°²È«²¼¸æ
2025Äê3ÔÂ11ÈÕ 8827Ì«Ñô¼¯ÍÅADLab¸´ÏÖ·ì϶

²Î¿¼Á´½Ó£º


[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq

[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc