Apache mod_jk½Ó¼û½ÚÔìÈÆ¹ý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-11-09

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-11759£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 7.3£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache Group Tomcat JK£¨mod_jk£©Connector 1.2.0-1.2.44


·ì϶¸ÅÊö


½üÈÕ£¬£¬£¬£¬£¬Apache Tomcat¹Ù·½°ä²¼ÁËmod_jk´æÔÚ½Ó¼û½ÚÔìÈÆ¹ý·ì϶£¨CVE-2018-11759£©µÄ°²È«¹«¸æ£¬£¬£¬£¬£¬Ä¿Ç°PoCÒѾ­¹«¿ª£¬£¬£¬£¬£¬ÇëÓйØÓû§ÒýÆð°ÑÎÈ£¬£¬£¬£¬£¬ÊµÊ±²ÉÈ¡·À±¸´ëÊ© ¡£¡£¡£¡£¡£


Apache Tomcat JK£¨mod_jk£©ConnectorÊÇÒ»¿îΪApache»òIISÌṩÏνӺó¶ÜTomcatµÄÄ£¿£¿£¿ £¿£¿ £¿£¿£¿é£¬£¬£¬£¬£¬ËüÖ§³Ö¼¯ÈººÍ¸ºÔØÆ½ºâµÈ ¡£¡£¡£¡£¡£ ´Ë·ì϶£¨CVE-2018-11759£©ÓëCVE-2018-1323ÀàËÆ£¬£¬£¬£¬£¬ÊÇÓÉÓÚApache Tomcat Web·þÎñÆ÷(httpd)ÓÃÓڹ淶ҪÇóõè¾¶µÄ´úÂ룬£¬£¬£¬£¬ÔÚÆ¥ÅäApache Tomcat JK(mod_jk)ÏÎ½ÓÆ÷ÖеÄURI-WorkerÓ³Éä֮ǰ£¬£¬£¬£¬£¬Ã»ÓÐÕýÈ·´¦ÖÃijЩ±ßÔµÇé¿ö£¨Èç¹ýÂË¡°£»£»£»£»£»¡±£©¶øµ¼Ö ¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓô˷ì϶¿Éͨ¹ý»ú¹Ø¶ñÒâÒªÇ󣬣¬£¬£¬£¬ÊµÏÖ½Ó¼û½ÚÔìÈÆ¹ý ¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


POC/EXP£º
https://github.com/immunIT/CVE-2018-11759

Óû§Ò²¿Éͨ¹ýPoC×ÔÐÐÅŲ鵱ǰËùʹÓõÄÄ£¿£¿£¿ £¿£¿ £¿£¿£¿éÊÇ·ñÊÜ´Ë·ì϶ӰÏ죬£¬£¬£¬£¬ÈçÏÂͼÔÚhttpd.confÅäÖÃÎļþÖнøÐÐÈçÏÂÅäÖ㬣¬£¬£¬£¬¼´¶Ô127.0.0.1µØÖ·µÄ½Ó¼û½øÐÐÁËÏÞ¶È ¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µ±Ê¹Óñ¾µØµØÖ·localhost½Ó¼ûʱ£¬£¬£¬£¬£¬»áÌáÐѱ»²»ÈݽӼû£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚµØÖ·ºóÔö³¤ÌØÊâ·ûºÅ¡°;¡±£¬£¬£¬£¬£¬¼´Èƹý´Ë½Ó¼ûÏÞ¶È ¡£¡£¡£¡£¡£Èô³öÏÖÏÂͼËùʾÇé¿ö£¬£¬£¬£¬£¬Ôò×¢Ã÷µ±Ç°ËùʹÓõÄmod_jkÊÜ´Ë·ì϶ӰÏì ¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÊÖ¹¤×Ô²é

Óû§¿Éͨ¹ý×ÔÐÐÅŲ鵱ǰËùʹÓð汾ÊÇ·ñÔÚÊÜÓ°ÏìÁìÓòÄÚ£¬£¬£¬£¬£¬À´ÅжÏÊÇ·ñÊÜ´æÔÚÍþв ¡£¡£¡£¡£¡£¾ßÌå²½ÖèÈçÏ£º

ʹÓÃstringsÖ±½Ó²é¿´mod_jk.so ¡£¡£¡£¡£¡£ºÅÁîÈçÏ£º
strings   mod_jk.so | grep mod_jk

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½¨¸´½¨Òé


Apache¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üе½1.2.46»ò¸üеİ汾£¬£¬£¬£¬£¬ÐγɶԴ˷ì϶³Ö¾ÃÓÐЧµÄ·À»¤ ¡£¡£¡£¡£¡£


Óû§±ØÒªµ½¹ÙÍøÏÂÔØ×îа汾ԭÂë½øÐбàÒë×°Ö㬣¬£¬£¬£¬ÏÂÔØÏνÓÈçÏ£º

https://archive.apache.org/dist/tomcat/tomcat-connectors/jk/tomcat-connectors-1.2.46-src.zip


²Î¿¼Á´½Ó


https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-11759