Apache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-12Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0232£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache Tomcat 8.5.0 to 8.5.39
Apache Tomcat 7.0.0 to 7.0.93
Îó²î¸ÅÊö
Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¸Ã³ÌÐòʵÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö¡£¡£¡£¡£
4ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚJRE½«ÏÂÁîÐвÎÊýת´ï¸øWindowsµÄ·½·¨±£´æ¹ýʧ£¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂCGI ServletÊܵ½Ô¶³ÌÖ´ÐдúÂëµÄ¹¥»÷¡£¡£¡£¡£
1. ϵͳΪWindows
2. ÆôÓÃÁËCGI Servlet£¨Ä¬ÒÔΪ¹Ø±Õ£©
3. ÆôÓÃÁËenableCmdLineArguments£¨Tomcat 9.0.*°æ±¾¼°¹Ù·½Î´À´Ðû²¼°æ±¾Ä¬ÒÔΪ¹Ø±Õ£©
ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлá°üÀ¨ÓÐÄ¿½ñTomcatµÄ°æ±¾ºÅ£¬£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÉó²é½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨Ä¿½ñµÄ°æ±¾¡£¡£¡£¡£
ÈôÊÇÄ¿½ñ°æ±¾ÔÚÓ°Ïì¹æÄ£ÄÚ£¬£¬£¬£¬£¬£¬£¬ÇÒÖª×ãÎó²î´¥·¢µÄ3¸öÌõ¼þ£¬£¬£¬£¬£¬£¬£¬ÔòÄ¿½ñϵͳ¿ÉÄܱ£´æÎ£º¦£¬£¬£¬£¬£¬£¬£¬ÇëÏà¹ØÓû§ÊµÊ±¸üС£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£
ÐÞ¸´½¨Òé
Apache¹Ù·½»¹Î´ÕýʽÐû²¼×îÐÂÐÞ¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§¼á³Ö¹Ø×¢£¬£¬£¬£¬£¬£¬£¬¹Ù·½¸üк󾡿ìÉý¼¶¾ÙÐзÀ»¤¡£¡£¡£¡£ÔÚ¹Ù·½Ðû²¼Ð°汾֮ǰ£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔ½«CGI Servlet³õʼ»¯²ÎÊýenableCmdLineArgumentsÉèÖÃΪfalseÀ´¾ÙÐÐÔÝʱ·À»¤¡£¡£¡£¡£
Ïêϸ²Ù×÷°ì·¨ÈçÏ£º
1¡¢ÔÚTomcat×°Ö÷¾¶µÄconfÎļþ¼ÐÏ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃ±à¼Æ÷·¿ªweb.xml¡£¡£¡£¡£
2¡¢ÕÒµ½enableCmdLineArguments²ÎÊý²¿·Ö£¬£¬£¬£¬£¬£¬£¬Ìí¼ÓÈçÏÂÉèÖãº
3¡¢ÖØÆôTomcatЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£ÉèÖÃÉúЧ¡£¡£¡£¡£
²Î¿¼Á´½Ó
http://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201904-525


¾©¹«Íø°²±¸11010802024551ºÅ