Apache TomcatÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÀ´Ï®£¨CVE-2025-24813£©£¬£¬£¬£¬¿·¢k8Ìṩ½â¾ö¼Æ»®
Ðû²¼Ê±¼ä 2025-03-13Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷£¬£¬£¬£¬ÆÕ±éÓÃÓÚÔËÐÐJava WebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£ËüʵÏÖÁËJava ServletºÍJavaServer PagesÊÖÒÕ£¬£¬£¬£¬ÌṩÁËÒ»¸öÔËÐÐÇéÐÎÀ´´¦Öóͷ£HTTPÇëÇó¡¢ÌìÉú¶¯Ì¬ÍøÒ³£¬£¬£¬£¬²¢Ö§³ÖWebSocketͨѶ¡£¡£¡£¡£¡£¡£TomcatÒÔÆäÎȹÌÐÔ¡¢ÎÞаÐÔºÍÒ×ÓÃÐÔ¶øÊܵ½¿ª·¢ÕßµÄÇàíù£¬£¬£¬£¬ÊÇ¿ª·¢ºÍ°²ÅÅJava WebÓ¦ÓõÄÖ÷Òª¹¤¾ßÖ®Ò»¡£¡£¡£¡£¡£¡£
2025Äê3Ô£¬£¬£¬£¬¿·¢k8¼à¿Øµ½Apache¹Ù·½Ðû²¼Îó²îΣº¦Í¨¸æ£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÆôÓÃÁËPartial PUTºÍDefaultServletдÈëȨÏÞµÄÇéÐΣ¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷ÕßÈÆ¹ý·¾¶Ð£Ñé»á¼ûÃô¸ÐÎļþ»òдÈëÌØ¶¨ÎļþÒÔÖ´ÐжñÒâµÄ·´ÐòÁл¯µ¼Ö´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
Îó²î±àºÅ | CVE-2025-24813 | |
Îó²îÆÀ¹À
| Îó²îʹÓÃÄÑ¶È | ÖÐ |
Îó²îʹÓÃÌõ¼þ | 11.0.0-M1 ¡Ü Apache Tomcat ¡Ü 11.0.2 10.1.0-M1 ¡Ü Apache Tomcat ¡Ü 10.1.34 9.0.0.M1 ¡Ü Apache Tomcat ¡Ü 9.0.98 | |
Îó²îÀàÐÍ | ÏÂÁîÖ´ÐÐ | |
¹ûÕæË®Æ½ | POCδ¹ûÕæ | |
Îó²î¸´ÏÖ½ØÍ¼


¼ì²âÒªÁì
½øÈëTomcat×°ÖÃĿ¼µÄbinĿ¼£¬£¬£¬£¬ÔËÐÐversion.bat£¨LinuxÔËÐÐversion.sh£©ºó£¬£¬£¬£¬¿ÉÉó²éÄ¿½ñµÄÈí¼þ°æ±¾ºÅ¡£¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾
11.0.0-M1 ¡Ü Apache Tomcat ¡Ü 11.0.2
10.1.0-M1 ¡Ü Apache Tomcat ¡Ü 10.1.34
9.0.0.M1 ¡Ü Apache Tomcat ¡Ü 9.0.98
ÐÞ¸´½¨Òé
1. եȡpartial PUT£ºÔÚ conf/web.xml ÖÐÐÞ¸Ä allowPartialPut ²ÎÊýΪfalse£¬£¬£¬£¬ÖØÆô Tomcat ÒÔʹÉèÖÃÉúЧ¡£¡£¡£¡£¡£¡£
2. ÑÏ¿á¿ØÖÆ DefaultServlet дÈëȨÏÞ£ºÈ·±£ readonly=true£¬£¬£¬£¬½ûÓÃËùÓÐδ¾ÊÚȨµÄ PUT/DELETE ÇëÇ󣬣¬£¬£¬½öÔÊÔÊÐíÐÅȪԴ»á¼ûÊÜÏÞĿ¼¡£¡£¡£¡£¡£¡£
Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®£º
ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾£º
Apache Tomcat >=11.0.3
Apache Tomcat >=10.1.35
Apache Tomcat >=9.0.99
¹Ù·½²¹¶¡ÏÂÔØµØµã£º
https://tomcat.apache.org/security-11.html
https://tomcat.apache.org/security-10.html
https://tomcat.apache.org/security-9.html
¶þ¡¢¿·¢k8¼Æ»®£º
1¡¢¿·¢k8¼ì²âÀà²úÆ·¼Æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬£¬£¬£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦¡£¡£¡£¡£¡£¡£
ÊÂÎñ¿âÏÂÔØµØµã£ºhttps://venustech.download.venuscloud.cn/
2¡¢¿·¢k8©ɨ²úÆ·¼Æ»®
£¨1£©¡°¿·¢k8Îó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£

£¨2£©¿·¢k8Îó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£

3¡¢¿·¢k8×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®
¿·¢k8×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬£¬£¬£¬¶ÔÈë¿â×ʲúApache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¾ÙÐÐÖÎÀí¡£¡£¡£¡£¡£¡£

4¡¢¿·¢k8Çå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®
Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬£¬£¬¾ÙÐйØÁªÕ½ÂÔÉèÖ㬣¬£¬£¬Á¬ÏµÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬£¬£¬£¬´Ó¶ø·¢Ã÷¡°Apache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£
1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬£¬£¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±Îó²îɨÃèʹÃü£¬£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£»£»£»£»£»£»

2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿£¿£¿£¿éÖУ¬£¬£¬£¬Ìí¼Ó¡°L2_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±£¬£¬£¬£¬Í¨¹ý¿·¢k8¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬£¬£¬£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º

̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬£¬£¬£¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓ㻣»£»£»£»£»
3£©Ìí¼Ó¡°L3_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±£¬£¬£¬£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±£¬£¬£¬£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬£¬£¬£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶȡ£¡£¡£¡£¡£¡£

4£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé
ƾ֤¶ÔApache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)µÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬£¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬£¬£¬£¬ÁýÕÖµÄTTP°üÀ¨£º
TA0001-³õʼ»á¼û£ºT1190-ʹÓùûÕæµÄÓ¦ÓÃЧÀÍ
TA0008-ºáÏòÒÆ¶¯£ºT1210-Ô¶³ÌЧÀÍÎó²îʹÓÃ
TA0011-ÏÂÁîÓë¿ØÖÆ£ºT1105-Èë¿Ú¹¤¾ß×ªÒÆ
TA0040-Ó°Ï죺T1485-Êý¾ÝÆÆËð

ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬£¬£¬£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬£¬£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£¡£¡£¡£¡£¡£
5¡¢¿·¢k8Öն˲úÆ·¼Æ»®
Ìì«‘ÖÕ¶ËÇå¾²Ò»Ì廯£¨EDR£©ÌṩÎó²îµÄרÏîÑéÖ¤¼ì²éÄÜÁ¦¿É¶ÔÎó²îפÁôÖն˾ÙÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬£¬£¬£¬Æ¥ÅäÎó²î×ʲú£¬£¬£¬£¬Ô¤·ÀÎó²î¹¥»÷Σº¦¡£¡£¡£¡£¡£¡£



¾©¹«Íø°²±¸11010802024551ºÅ