¡¾Îó²îͨ¸æ¡¿Apache TomcatÐÅϢй¶Îó²î£¨CVE-2023-28708£©
Ðû²¼Ê±¼ä 2023-03-23Ò»¡¢Îó²î¸ÅÊö
CVE ID | CVE-2023-28708 | ·¢Ã÷ʱ¼ä | 2023-03-23 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ËùÐèȨÏÞ | ||
¹¥»÷ÖØÆ¯ºó | Óû§½»»¥ | ||
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
Apache TomcatÊÇÒ»¸öÊ¢ÐеĿªÔ´WebЧÀÍÆ÷ºÍJava´úÂëµÄServletÈÝÆ÷¡£¡£¡£¡£
3ÔÂ23ÈÕ£¬£¬£¬£¬¼øºÚµ£±£ÍøVSRC¼à²âµ½Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËApache TomcatÖеÄÒ»¸öÐÅϢй¶Îó²î£¨CVE-2023-28708£©¡£¡£¡£¡£
µ±Apache TomcatµÄRemoteIpFilterºÍHTTP·´ÏòÊðÀíÒ»ÆðʹÓÃʱ£¬£¬£¬£¬ÈôÊÇÇëÇóÖаüÀ¨ÉèÖÃΪhttpsµÄX-Forwarded-Proto±êÍ·£¬£¬£¬£¬ÔòTomcat½¨ÉèµÄ»á»°cookieδ°üÀ¨secureÊôÐÔ£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÓû§ÊðÀíͨ¹ý²»Çå¾²µÄͨµÀ´«Êä»á»°cookie£¬£¬£¬£¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Apache Tomcat°æ±¾£º11.0.0-M1 - 11.0.0-M2
Apache Tomcat°æ±¾£º10.1.0-M1 - 10.1.5
Apache Tomcat°æ±¾£º9.0.0-M1 - 9.0.71
Apache Tomcat°æ±¾£º8.5 .0 - 8.5.85
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
Apache Tomcat°æ±¾£º>= 11.0.0-M3
Apache Tomcat°æ±¾£º>= 10.1.6
Apache Tomcat°æ±¾£º>= 9.0.72
Apache Tomcat°æ±¾£º>= 8.5.86
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://tomcat.apache.org/security-11.html
https://lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-03-23 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£
5.2 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º