CVE-2020-11996 | Apache Tomcat HTTP/2¾Ü¾øÐ§ÀÍÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-290x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-11996 |
ʱ ¼ä |
2020-06-29 |
ÀàÐÍ |
DOS |
µÈ ¼¶ |
¸ßΣ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5 Apache Tomcat 9.0.0.M1ÖÁ9.0.35 Apache Tomcat 8.5.0ÖÁ8.5.55 |
0x01 Îó²îÏêÇé
Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¸Ã³ÌÐòʵÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö£¬£¬£¬£¬£¬£¬£¬ÊÇ¿ª·¢ºÍµ÷ÊÔJSP ³ÌÐòµÄÊ×Ñ¡¡£¡£¡£ApacheÖ»Ö§³Ö¾²Ì¬ÍøÒ³£¬£¬£¬£¬£¬£¬£¬µ«Ïñphp,cgi,jspµÈ¶¯Ì¬ÍøÒ³¾ÍÐèÒªTomcatÀ´´¦Öóͷ£¡£¡£¡£
2020Äê6ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache TomcatÖеÄHTTP/2¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-11996£©¡£¡£¡£¸ÃÎó²îÔ´ÓÚ¶ñÒâµÄHTTP/2ÇëÇóÐòÁпÉÄܻᵼÖ³¤´ï¼¸ÃëÖÓµÄCPU¸ßʹÓÃÂÊ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý·¢ËÍ´ó×ڵĴËÀàÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂЧÀÍÆ÷¾Ü¾øÏìÓ¦£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖDoS¹¥»÷¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¸ÃÎó²îÓ°ÏìApache Tomcat 10.0.0-M1ÖÁ10.0.0-M5°æ±¾¡¢9.0.0.M1ÖÁ9.0.35°æ±¾ºÍ8.5.0ÖÁ8.5.55°æ±¾£¬£¬£¬£¬£¬£¬£¬¹Ù·½ÒÑÐû²¼×îа汾£¬£¬£¬£¬£¬£¬£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶£¬£¬£¬£¬£¬£¬£¬ÏêÇéÈçÏ£º
1. Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5 °æ±¾µÄÓû§ÇëÉý¼¶µ½10.0.0-M6»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-10.cgi
2. Apache Tomcat 9.0.0.M1ÖÁ9.0.35 °æ±¾µÄÓû§ÇëÉý¼¶µ½9.0.36»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-90.cgi
3. Apache Tomcat 8.5.0ÖÁ8.5.55 °æ±¾µÄÓû§ÇëÉý¼¶µ½8.5.56»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-80.cgi
0x03 Ïà¹ØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-11996
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E
http://mail-archives.us.apache.org/mod_mbox/www-announce/202006.mbox/%3Cfd56bc1d-1219-605b-99c7-946bf7bd8ad4%40apache.org%3E
0x05 ʱ¼äÏß
2020-06-25 ApacheÐû²¼Ç徲ͨ¸æ
2020-06-29 VSRCÐû²¼Îó²îͨ¸æ