Apache TomcatÎļþ°üÀ¨Îó²î[CVE-2020-1938] ÄϹ¬NGÓéÀÖÌṩ½â¾ö¼Æ»®
Ðû²¼Ê±¼ä 2020-02-212ÔÂ20ÈÕ£¬£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼¹ØÓÚApache TomcatµÄÇ徲ͨ¸æ¡£¡£¡£Apache TomcatÎļþ°üÀ¨Îó²î£¨CNVD-2020-10487£¬£¬¶ÔÓ¦CVE-2020-1938£©¡£¡£¡£Tomcat AJPÐÒéÓÉÓÚ±£´æÊµÏÖȱÏݵ¼ÖÂÏà¹Ø²ÎÊý¿É¿Ø£¬£¬¹¥»÷ÕßʹÓøÃÎó²î¿Éͨ¹ý½á¹¹Ìض¨²ÎÊý£¬£¬¶ÁȡЧÀÍÆ÷webappϵÄí§ÒâÎļþ¡£¡£¡£ÈôЧÀÍÆ÷¶Ëͬʱ±£´æÎļþÉÏ´«¹¦Ð§£¬£¬¹¥»÷Õ߿ɽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëµÄÖ´ÐС£¡£¡£
? Îó²îʹÓãº
? Îó²îÓ°Ïì°æ±¾£º
Tomcat 6.x
Tomcat 7.x<7.0.100
Tomcat 8.x<8.5.51
Tomcat 9.x<9.0.31
ÄϹ¬NGÓéÀÖ½â¾ö¼Æ»®
Ò»¡¢ ½«TomcatÁ¬Ã¦Éý¼¶µ½9.0.31¡¢8.5.51»ò7.0.100°æ±¾¾ÙÐÐÐÞ¸´»ò½ûÓÃAJPÐÒé¡£¡£¡£
¶þ¡¢ ²úÆ·¼ì²âÓë·À»¤£º
1¡¢ÒѰ²ÅÅÄϹ¬NGÓéÀÖIDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æÔòÒѾÏ·¢²¢Ó¦Ó㬣¬¼´¿ÉÓÐÓüì²â»ò×è¶Ï¹¥»÷£ºTCP_Tomcat_AJP13_í§ÒâÎļþ¶ÁÈ¡[CVE-2020-1938]¡£¡£¡£
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
£¨3£©ÌìÇåWebÓ¦ÓÃÇå¾²Íø¹Ø±¨¾¯½ØÍ¼£º
2¡¢Îó²îɨÃè
ÄϹ¬NGÓéÀÖÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2ÔÂ21ÈÕ½ôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐмì²â£¬£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ·Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£¡£6070°æ±¾Éý¼¶°üΪ607000275£¬£¬Éý¼¶°üÏÂÔØµØµã£º
/article/type/1/146.html
ÇëʹÓÃÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â£¬£¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ