Apache TomcatÎļþÔ̺¬·ì϶[CVE-2020-1938] 8827Ì«Ñô¼¯ÍÅÌṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2020-02-212ÔÂ20ÈÕ£¬£¬£¬£¬£¬¹ú¶ÈÐÅÏ¢°²È«·ì϶¹²ÏíÆ½Ì¨£¨CNVD£©°ä²¼¹ØÓÚApache TomcatµÄ°²È«²¼¸æ¡£¡£¡£¡£¡£Apache TomcatÎļþÔ̺¬·ì϶£¨CNVD-2020-10487£¬£¬£¬£¬£¬¶ÔÓ¦CVE-2020-1938£©¡£¡£¡£¡£¡£Tomcat AJPºÍ̸ÓÉÓÚ´æÔÚʵÏÖȱµãµ¼ÖÂÓйزÎÊý¿É¿Ø£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓø÷ì϶¿Éͨ¹ý»ú¹ØÌض¨²ÎÊý£¬£¬£¬£¬£¬¶ÁÈ¡·þÎñÆ÷webappϵÄËÁÒâÎļþ¡£¡£¡£¡£¡£Èô·þÎñÆ÷¶Ëͬʱ´æÔÚÎļþÉÏ´«Ö°ÄÜ£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëµÄÖ´ÐС£¡£¡£¡£¡£
? ·ì϶ÀûÓãº
? ·ì϶ӰÏì°æ±¾£º
Tomcat 6.x
Tomcat 7.x<7.0.100
Tomcat 8.x<8.5.51
Tomcat 9.x<9.0.31
8827Ì«Ñô¼¯ÍŽâ¾ö¹æ»®
Ò»¡¢ ½«TomcatÁ¢¼´Éý¼¶µ½9.0.31¡¢8.5.51»ò7.0.100°æ±¾½øÐн¨¸´»ò½ûÓÃAJPºÍ̸¡£¡£¡£¡£¡£
¶þ¡¢ ²úÆ·¼ì²âÓë·À»¤£º
1¡¢ÒѲ¿Êð8827Ì«Ñô¼¯ÍÅIDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾÏ·¢²¢ÀûÓ㬣¬£¬£¬£¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£ºTCP_Tomcat_AJP13_ËÁÒâÎļþ¶ÁÈ¡[CVE-2020-1938]¡£¡£¡£¡£¡£
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
£¨3£©ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º
2¡¢·ì϶ɨÃè
8827Ì«Ñô¼¯ÍÅÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2ÔÂ21ÈÕ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬£¬£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐмì²â£¬£¬£¬£¬£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ··ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£¡£¡£¡£6070°æ±¾Éý¼¶°üΪ607000275£¬£¬£¬£¬£¬Éý¼¶°üÏÂÔØµØÖ·£º
/article/type/1/146.html
ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬£¬£¬£¬£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ