¸Õ¸Õ£¬¾ÅÓÎÀϸçÔÆÕë¶ÔApache TomcatÎļþ°üÀ¨Îó²îµÄÔÚÏß¼ì²âÕýʽÉÏÏß
2020-02-21
2ÔÂ20ÈÕ£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼ÁËÒ»Ôò¹ØÓÚApache Tomcat±£´æÎļþ°üÀ¨Îó²îµÄÇ徲ͨ¸æ£¨CNVD-2020-10487£¬¶ÔÓ¦CVE-2020-1938£©¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼Çå¾²Ñо¿ÍŶӵÚһʱ¼ä¶Ô´Ë´ÎÎó²î¾ÙÐÐÑо¿£¬²¢½ôÆÈÉÏÏßÁËÔÚÏß¼ì²â¹¤¾ß¡£
Äú¿ÉÒÔÉϰ¶¾ÅÓÎÀϸçÔÆhttps://cloud.nsfocus.com£¬½øÈë“Îó²îÍþв-½ôÆÈÎó²î”£¬°´ÒªÇóÊäÈë´ý¼ì²âµÄÕ¾µãÐÅÏ¢£¬µã»÷“Á¬Ã¦¼ì²â”¼´¿É¡£

Îó²î×ÛÊö
2ÔÂ20ÈÕ£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼ÁËÒ»Ôò¹ØÓÚApache Tomcat±£´æÎļþ°üÀ¨Îó²îµÄÇ徲ͨ¸æ¡£Í¨¸æÖÐÌåÏÖ£¬±£´æÓÚApache TomcatÖеÄÎļþ°üÀ¨Îó²î£¨CNVD-2020-10487£¬¶ÔÓ¦CVE-2020-1938£©¿Éʹ¹¥»÷ÕßÔÚδÊÚȨµÄÇéÐÎÏÂÔ¶³Ì¶ÁÈ¡ÌØ¶¨Ä¿Â¼ÏµÄí§ÒâÎļþ¡£Îó²îÔ´ÓÚTomcat AJPÐÒéʵÏÖÖеÄȱÏÝ£¬Ê¹µÃÏà¹Ø²ÎÊý¿É¿Ø¡£¹¥»÷Õßͨ¹ýÏòAJPÐÒé¶Ë¿Ú£¨Ä¬ÈÏ8009£©·¢ËÍÈ«ÐĽṹµÄÊý¾Ý£¬¿É¶ÁÈ¡·þÎñÆ÷webappĿ¼ÏµÄí§ÒâÎļþ£¬ºÃ±ÈÉèÖÃÎļþ¡¢Ô´´úÂëµÈ¡£²¢ÇÒÈôÊÇ·þÎñÆ÷¶ËÓÐÎļþÉÏ´«¹¦Ð§£¬ÄÇô¹¥»÷Õß»¹¿ÉÄܽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëµÄÖ´ÐС£
²Î¿¼Á´½Ó£º
https://www.cnvd.org.cn/webinfo/show/5415
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì²úÆ·°æ±¾£º
Tomcat 6 (ÒѲ»ÊÜά»¤)
Tomcat 7 Version < 7.0.100
Tomcat 8 Version < 8.5.51
Tomcat 9 Version < 9.0.31
²»ÊÜÓ°Ïì²úÆ·°æ±¾£º
Tomcat 7 Version >= 7.0.100
Tomcat 8 Version >= 8.5.51
Tomcat 9 Version >= 9.0.31
½â¾ö¼Æ»®
Apache¹Ù·½ÒѾÐû²¼Ð°汾ÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤£¬ÎÞ·¨Á¬Ã¦¾ÙÐиüеÄÓû§¿É²Î¿¼ CNVDͨ¸æ½ÓÄÉÔÝʱ»º½â²½·¥¡£
а汾ÏÂÔØµØµã£º
https://github.com/apache/tomcat/releases
http://tomcat.apache.org/
CNVD ͨ¸æ£º
https://www.cnvd.org.cn/webinfo/show/5415

¾ÅÓÎÀϸçÔÆ







