Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-12

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-0232£¬ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache Tomcat 9.0.0.M1 to 9.0.17
Apache Tomcat 8.5.0 to 8.5.39

Apache Tomcat 7.0.0 to 7.0.93


·ì϶¸ÅÊö


Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÀûÓ÷þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·¨Ê½ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö¡£¡£¡£¡£¡£¡£¡£¡£


4ÔÂ11ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½°ä²¼°²È«¹«¸æ£¬ £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚJRE½«ºÅÁîÐвÎÊý´«µÝ¸øWindowsµÄ·½Ê½´æÔÚÃýÎó£¬ £¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂCGI ServletÊܵ½Ô¶³ÌÖ´ÐдúÂëµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


´¥·¢¸Ã·ì϶±ØÒªÍ¬Ê±Âú×ãÒÔÏÂǰÌᣬ £¬£¬£¬£¬£¬£¬£¬ÇëÓйØÓû§ÒýÆð¹Ø×¢£º
1. ϵͳΪWindows
2. ÆôÓÃÁËCGI Servlet£¨Ä¬ÒÔΪ¹Ø¹Ø£©

3. ÆôÓÃÁËenableCmdLineArguments£¨Tomcat 9.0.*°æ±¾¼°¹Ù·½½«À´°ä²¼°æ±¾Ä¬ÒÔΪ¹Ø¹Ø£©


°æ±¾ÅŲéÈçÏ£º
ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлáÔ̺¬Óе±Ç°TomcatµÄ°æ±¾ºÅ£¬ £¬£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ý²é¿´½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨µ±Ç°µÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£

 

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÈôÊǽâѹºóµÄTomcatĿ¼Ãû³Æ±»½¨»Ú¸Ä£¬ £¬£¬£¬£¬£¬£¬£¬»òÕßͨ¹ýWindows Service Installer·½Ê½×°Ö㬠£¬£¬£¬£¬£¬£¬£¬¿ÉʹÓÃÈí¼þ×Ô´øµÄversionÄ£¿£¿£¿£¿£¿£¿£¿éÀ´»ñÈ¡µ±Ç°µÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£½øÈëtomcat×°ÖÃĿ¼µÄbinĿ¼£¬ £¬£¬£¬£¬£¬£¬£¬ÊäÈëºÅÁîversion.batºó£¬ £¬£¬£¬£¬£¬£¬£¬¿É²é¿´µ±Ç°µÄÈí¼þ°æ±¾ºÅ¡£¡£¡£¡£¡£¡£¡£¡£

 

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÈôÊǵ±Ç°°æ±¾ÔÚÓ°ÏìÁìÓòÄÚ£¬ £¬£¬£¬£¬£¬£¬£¬ÇÒÂú×ã·ì϶´¥·¢µÄ3¸öǰÌᣬ £¬£¬£¬£¬£¬£¬£¬Ôòµ±Ç°ÏµÍ³¿ÉÄÜ´æÔÚ·çÏÕ£¬ £¬£¬£¬£¬£¬£¬£¬ÇëÓйØÓû§ÊµÊ±¸üС£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Apache¹Ù·½»¹Î´Õýʽ°ä²¼×îн¨¸´°æ±¾£¬ £¬£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§Î¬³Ö¹Ø×¢£¬ £¬£¬£¬£¬£¬£¬£¬¹Ù·½¸üк󾡿ìÉý¼¶½øÐзÀ»¤¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¹Ù·½°ä²¼Ð°汾֮ǰ£¬ £¬£¬£¬£¬£¬£¬£¬Óû§Äܹ»½«CGI Servlet³õʼ»¯²ÎÊýenableCmdLineArgumentsÉèÖÃΪfalseÀ´½øÐÐһʱ·À»¤¡£¡£¡£¡£¡£¡£¡£¡£


¾ßÌå²Ù×÷²½ÖèÈçÏ£º

1¡¢ÔÚTomcat×°ÖÃõè¾¶µÄconfÎļþ¼ÐÏ£¬ £¬£¬£¬£¬£¬£¬£¬Ê¹Óñà×ëÆ÷´ò¿ªweb.xml¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2¡¢ÕÒµ½enableCmdLineArguments²ÎÊý²¿ÃÅ£¬ £¬£¬£¬£¬£¬£¬£¬Ôö³¤ÈçÏÂÅäÖãº


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


3¡¢³ÁÆôTomcat·þÎñ£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£ÅäÖÃÉúЧ¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201904-525