Apache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-12

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-0232£¬£¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache Tomcat 9.0.0.M1 to 9.0.17
Apache Tomcat 8.5.0 to 8.5.39

Apache Tomcat 7.0.0 to 7.0.93


Îó²î¸ÅÊö


Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¸Ã³ÌÐòʵÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö¡£¡£¡£¡£¡£¡£¡£


4ÔÂ11ÈÕ£¬£¬ £¬£¬ £¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬ £¬£¬ £¬£¬ÓÉÓÚJRE½«ÏÂÁîÐвÎÊýת´ï¸øWindowsµÄ·½·¨±£´æ¹ýʧ£¬£¬ £¬£¬ £¬£¬»áµ¼ÖÂCGI ServletÊܵ½Ô¶³ÌÖ´ÐдúÂëµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£


´¥·¢¸ÃÎó²îÐèҪͬʱ֪×ãÒÔÏÂÌõ¼þ£¬£¬ £¬£¬ £¬£¬ÇëÏà¹ØÓû§ÒýÆð¹Ø×¢£º
1. ϵͳΪWindows
2. ÆôÓÃÁËCGI Servlet£¨Ä¬ÒÔΪ¹Ø±Õ£©

3. ÆôÓÃÁËenableCmdLineArguments£¨Tomcat 9.0.*°æ±¾¼°¹Ù·½Î´À´Ðû²¼°æ±¾Ä¬ÒÔΪ¹Ø±Õ£©


°æ±¾ÅŲéÈçÏ£º
ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлá°üÀ¨ÓÐÄ¿½ñTomcatµÄ°æ±¾ºÅ£¬£¬ £¬£¬ £¬£¬Óû§¿Éͨ¹ýÉó²é½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨Ä¿½ñµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÈôÊǽâѹºóµÄTomcatĿ¼Ãû³Æ±»Ð޻ڸ쬣¬ £¬£¬ £¬£¬»òÕßͨ¹ýWindows Service Installer·½·¨×°Ö㬣¬ £¬£¬ £¬£¬¿ÉʹÓÃÈí¼þ×Ô´øµÄversionÄ£¿£¿£¿£¿£¿£¿£¿éÀ´»ñȡĿ½ñµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£½øÈëtomcat×°ÖÃĿ¼µÄbinĿ¼£¬£¬ £¬£¬ £¬£¬ÊäÈëÏÂÁîversion.batºó£¬£¬ £¬£¬ £¬£¬¿ÉÉó²éÄ¿½ñµÄÈí¼þ°æ±¾ºÅ¡£¡£¡£¡£¡£¡£¡£

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÈôÊÇÄ¿½ñ°æ±¾ÔÚÓ°Ïì¹æÄ£ÄÚ£¬£¬ £¬£¬ £¬£¬ÇÒÖª×ãÎó²î´¥·¢µÄ3¸öÌõ¼þ£¬£¬ £¬£¬ £¬£¬ÔòÄ¿½ñϵͳ¿ÉÄܱ£´æÎ£º¦£¬£¬ £¬£¬ £¬£¬ÇëÏà¹ØÓû§ÊµÊ±¸üС£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


Apache¹Ù·½»¹Î´ÕýʽÐû²¼×îÐÂÐÞ¸´°æ±¾£¬£¬ £¬£¬ £¬£¬ÇëÊÜÓ°ÏìµÄÓû§¼á³Ö¹Ø×¢£¬£¬ £¬£¬ £¬£¬¹Ù·½¸üк󾡿ìÉý¼¶¾ÙÐзÀ»¤¡£¡£¡£¡£¡£¡£¡£ÔÚ¹Ù·½Ðû²¼Ð°汾֮ǰ£¬£¬ £¬£¬ £¬£¬Óû§¿ÉÒÔ½«CGI Servlet³õʼ»¯²ÎÊýenableCmdLineArgumentsÉèÖÃΪfalseÀ´¾ÙÐÐÔÝʱ·À»¤¡£¡£¡£¡£¡£¡£¡£


Ïêϸ²Ù×÷°ì·¨ÈçÏ£º

1¡¢ÔÚTomcat×°Ö÷¾¶µÄconfÎļþ¼ÐÏ£¬£¬ £¬£¬ £¬£¬Ê¹Óñ༭Æ÷·­¿ªweb.xml¡£¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2¡¢ÕÒµ½enableCmdLineArguments²ÎÊý²¿·Ö£¬£¬ £¬£¬ £¬£¬Ìí¼ÓÈçÏÂÉèÖãº


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3¡¢ÖØÆôTomcatЧÀÍ£¬£¬ £¬£¬ £¬£¬ÒÔÈ·±£ÉèÖÃÉúЧ¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201904-525