¡¾Ô¤¾¯Í¨¸æ¡¿Apache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2019-0232
2019-04-11
ÍâµØÊ±¼ä4ÔÂ10ÈÕ£¬Apache¹Ù·½Ðû²¼Í¨¸æ³Æ½«ÔÚ×îа汾ÖÐÐÞ¸´Ò»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0232£©¡£ÔÚÆôÓÃÁËenableCmdLineArgumentsµÄWindowsÉÏÔËÐÐʱ£¬ÓÉÓÚJRE½«ÏÂÁîÐвÎÊýת´ï¸øWindowsµÄ·½·¨±£´æ¹ýʧ£¬CGI ServletºÜÈÝÒ×Êܵ½Ô¶³ÌÖ´ÐдúÂëµÄ¹¥»÷¡£CGI ServletĬÈÏÊǹرյġ£
Îó²îÏêϸÐÅÏ¢¿É²Î¿¼£º
ÊÜÓ°ÏìµÄ°æ±¾
- Apache Tomcat 9.0.0.M1 to 9.0.17
- Apache Tomcat 8.5.0 to 8.5.39
- Apache Tomcat 7.0.0 to 7.0.93
²»ÊÜÓ°ÏìµÄ°æ±¾
- Apache Tomcat 9.0.18
- Apache Tomcat 8.5.40
- Apache Tomcat 7.0.94
½â¾ö¼Æ»®
Apache¹Ù·½»¹Î´ÕýʽÐû²¼ÒÔÉÏ×îа汾£¬ÊÜÓ°ÏìµÄÓû§Çë¼á³Ö¹Ø×¢£¬ÔÚ¹Ù·½¸üк󾡿ìÉý¼¶¾ÙÐзÀ»¤¡£Óë´Ëͬʱ£¬Óû§¿ÉÒÔ½«CGI Servlet³õʼ»¯²ÎÊýenableCmdLineArgumentsÉèÖÃΪfalseÀ´¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
½â¾ö½¨Òé
°æ±¾ÅŲé
ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлá°üÀ¨ÓÐÄ¿½ñTomcatµÄ°æ±¾ºÅ£¬Óû§¿Éͨ¹ýÉó²é½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨Ä¿½ñµÄ°æ±¾¡£
ÈôÊǽâѹºóµÄTomcatĿ¼Ãû³Æ±»Ð޻ڸ쬻òÕßͨ¹ýWindows Service Installer·½·¨×°Ö㬿ÉʹÓÃÈí¼þ×Ô´øµÄversionÄ£¿éÀ´»ñȡĿ½ñµÄ°æ±¾¡£½øÈëtomcat×°ÖÃĿ¼µÄbinĿ¼£¬ÊäÈëÏÂÁîversion.batºó£¬¿ÉÉó²éÄ¿½ñµÄÈí¼þ°æ±¾ºÅ¡£
ÈôÊÇÄ¿½ñ°æ±¾ÔÚÓ°Ïì¹æÄ£ÄÚ£¬ÇÒÖª×ãÎó²î´¥·¢µÄ3¸öÌõ¼þ£¬ÔòÄ¿½ñϵͳ¿ÉÄܱ£´æÎ£º¦£¬ÇëÏà¹ØÓû§ÊµÊ±¸üС£
¹Ø±ÕenableCmdLineArguments²ÎÊý
Apache¹Ù·½»¹Î´ÕýʽÐû²¼×îÐÂÐÞ¸´°æ±¾£¬ÇëÊÜÓ°ÏìµÄÓû§¼á³Ö¹Ø×¢£¬¹Ù·½¸üк󾡿ìÉý¼¶¾ÙÐзÀ»¤¡£ÔÚ¹Ù·½Ðû²¼Ð°汾֮ǰ£¬Óû§¿ÉÒÔ½«CGI Servlet³õʼ»¯²ÎÊýenableCmdLineArgumentsÉèÖÃΪfalseÀ´¾ÙÐÐÔÝʱ·À»¤¡£Ïêϸ²Ù×÷°ì·¨ÈçÏ£º
1¡¢ÔÚTomcat×°Ö÷¾¶µÄconfÎļþ¼ÐÏ£¬Ê¹ÓÃ±à¼Æ÷·¿ªweb.xml¡£
2¡¢ÕÒµ½enableCmdLineArguments²ÎÊý²¿·Ö£¬Ìí¼ÓÈçÏÂÉèÖãº
3¡¢ÖØÆôTomcat·þÎñ£¬ÒÔÈ·±£ÉèÖÃÉúЧ¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐÉúÒ⣬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ





