Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | TornadoÈÕÖ¾ÆÊÎöÆ÷¾Ü¾øÐ§ÀÍÎó²î |
CVE ID | CVE-2025-47287 |
Îó²îÀàÐÍ | ¾Ü¾øÐ§ÀÍ | ·¢Ã÷ʱ¼ä | 2025-05-16 |
Îó²îÆÀ·Ö | 7.5 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
TornadoÊÇÒ»¸ö¸ßÐÔÄܵÄWeb¿ò¼ÜºÍÒì²½ÍøÂç¿â£¬£¬£¬£¬£¬×¨Îª´¦Öóͷ£´ó¹æÄ£²¢·¢ÅþÁ¬Éè¼Æ¡£¡£¡£¡£¡£ËüÖ§³Ö·ÇÛÕ±ÕI/O£¬£¬£¬£¬£¬Äܹ»´¦Öóͷ£³ÉǧÉÏÍòµÄÅþÁ¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚʵʱWebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£TornadoÌṩÁËÒ»¸ö¼òÆÓÒ×ÓõÄWebЧÀÍÆ÷£¬£¬£¬£¬£¬²¢Ö§³ÖWebSockets¡¢³¤ÂÖѯµÈÐÒ飬£¬£¬£¬£¬ÆÕ±éÓÃÓÚ¹¹½¨¸ßЧµÄʵʱͨѶϵͳ¡£¡£¡£¡£¡£ËüÊÊÓÃÓÚÐèÒª¸ßÍÌÍÂÁ¿ºÍµÍÑӳٵij¡¾°£¬£¬£¬£¬£¬Èç̸ÌìÓ¦Óá¢ÍÆËÍ֪ͨµÈ¡£¡£¡£¡£¡£2025Äê5ÔÂ16ÈÕ£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Tornado¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬Ö¸³öTornadoµÄmultipart/form-dataÆÊÎöÆ÷±£´æÈÕÖ¾¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£¸ÃÆÊÎöÆ÷ÔÚĬÈÏÆôÓõÄÇéÐÎÏ£¬£¬£¬£¬£¬µ±Óöµ½Ìض¨¹ýʧʱ£¬£¬£¬£¬£¬»á¼Í¼ÖÒÑÔÐÅÏ¢²¢¼ÌÐøÆÊÎöºóÐøÊý¾Ý¡£¡£¡£¡£¡£ÕâÖÖ´¦Öóͷ£·½·¨Ê¹¹¥»÷ÕßÄܹ»·¢ËͶñÒâÇëÇ󣬣¬£¬£¬£¬ÌìÉú´ó×ÚÖÒÑÔÈÕÖ¾£¬£¬£¬£¬£¬´Ó¶øÏûºÄϵͳ×ÊÔ´²¢µ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©¹¥»÷¡£¡£¡£¡£¡£ÓÉÓÚTornadoµÄÈÕÖ¾×ÓϵͳÊÇͬ²½µÄ£¬£¬£¬£¬£¬Îó²îµÄÓ°Ïì½øÒ»²½¼Ó¾ç£¬£¬£¬£¬£¬µ¼ÖÂÈÕÖ¾´¦Öóͷ£ÑÓ³Ù£¬£¬£¬£¬£¬½ø¶øÓ°ÏìϵͳÐÔÄÜ¡£¡£¡£¡£¡£Îó²î¼¶±ð¸ßΣ£¬£¬£¬£¬£¬Îó²îÆÀ·Ö7.5·Ö¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶µ½Tornado 6.5.0°æ±¾¡£¡£¡£¡£¡£ÏÂÔØÁ´½Ó£ºhttps://github.com/tornadoweb/tornado/tags/3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£3.4 ²Î¿¼Á´½Ó
https://github.com/tornadoweb/tornado/tagshttps://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5mhttps://nvd.nist.gov/vuln/detail/CVE-2025-47287