Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-12·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0232£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache Tomcat 8.5.0 to 8.5.39
Apache Tomcat 7.0.0 to 7.0.93
·ì϶¸ÅÊö
Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÀûÓ÷þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·¨Ê½ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö¡£¡£¡£¡£¡£¡£¡£¡£
4ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚJRE½«ºÅÁîÐвÎÊý´«µÝ¸øWindowsµÄ·½Ê½´æÔÚÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂCGI ServletÊܵ½Ô¶³ÌÖ´ÐдúÂëµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
1. ϵͳΪWindows
2. ÆôÓÃÁËCGI Servlet£¨Ä¬ÒÔΪ¹Ø¹Ø£©
3. ÆôÓÃÁËenableCmdLineArguments£¨Tomcat 9.0.*°æ±¾¼°¹Ù·½½«À´°ä²¼°æ±¾Ä¬ÒÔΪ¹Ø¹Ø£©
ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлáÔ̺¬Óе±Ç°TomcatµÄ°æ±¾ºÅ£¬£¬£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ý²é¿´½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨µ±Ç°µÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÈôÊǵ±Ç°°æ±¾ÔÚÓ°ÏìÁìÓòÄÚ£¬£¬£¬£¬£¬£¬£¬£¬ÇÒÂú×ã·ì϶´¥·¢µÄ3¸öǰÌᣬ£¬£¬£¬£¬£¬£¬£¬Ôòµ±Ç°ÏµÍ³¿ÉÄÜ´æÔÚ·çÏÕ£¬£¬£¬£¬£¬£¬£¬£¬ÇëÓйØÓû§ÊµÊ±¸üС£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Apache¹Ù·½»¹Î´Õýʽ°ä²¼×îн¨¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§Î¬³Ö¹Ø×¢£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½¸üк󾡿ìÉý¼¶½øÐзÀ»¤¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¹Ù·½°ä²¼Ð°汾֮ǰ£¬£¬£¬£¬£¬£¬£¬£¬Óû§Äܹ»½«CGI Servlet³õʼ»¯²ÎÊýenableCmdLineArgumentsÉèÖÃΪfalseÀ´½øÐÐһʱ·À»¤¡£¡£¡£¡£¡£¡£¡£¡£
¾ßÌå²Ù×÷²½ÖèÈçÏ£º
1¡¢ÔÚTomcat×°ÖÃõè¾¶µÄconfÎļþ¼ÐÏ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹Óñà×ëÆ÷´ò¿ªweb.xml¡£¡£¡£¡£¡£¡£¡£¡£
2¡¢ÕÒµ½enableCmdLineArguments²ÎÊý²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬Ôö³¤ÈçÏÂÅäÖãº
3¡¢³ÁÆôTomcat·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£ÅäÖÃÉúЧ¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
http://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201904-525


¾©¹«Íø°²±¸11010802024551ºÅ