¡¾Íþвͨ¸æ¡¿Apache Tomcat Îļþ°üÀ¨Îó²î£¨CVE-2020-1938£©
2020-02-20
Ò». Îó²î¸ÅÊö
2ÔÂ20ÈÕ£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼ÁËApache TomcatÎļþ°üÀ¨Îó²î£¨CNVD-2020-10487/CVE-2020-1938£©¡£¸ÃÎó²îÊÇÓÉÓÚTomcat AJPÐÒé±£´æÈ±Ïݶøµ¼Ö£¬¹¥»÷ÕßʹÓøÃÎó²î¿Éͨ¹ý½á¹¹Ìض¨²ÎÊý£¬¶ÁÈ¡·þÎñÆ÷webappϵÄí§ÒâÎļþ¡£ÈôÄ¿µÄ·þÎñÆ÷ͬʱ±£´æÎļþÉÏ´«¹¦Ð§£¬¹¥»÷Õ߿ɽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£ÏÖÔÚ£¬³§ÉÌÒÑÐû²¼Ð°汾Íê³ÉÎó²îÐÞ¸´¡£
TomcatÊÇApacheÈí¼þ»ù½ð»áÖеÄÒ»¸öÖ÷ÒªÏîÄ¿£¬ÐÔÄÜÎȹÌÇÒÃâ·Ñ£¬ÊÇÏÖÔÚ½ÏΪʢÐеÄWebÓ¦Ó÷þÎñÆ÷¡£ÓÉÓÚTomcatÓ¦ÓùæÄ£½Ï¹ã£¬Òò´Ë±¾´Îͨ¸æµÄÎó²îÓ°Ïì¹æÄ£½Ï´ó£¬ÇëÏà¹ØÓû§ÊµÊ±½ÓÄÉ·À»¤²½·¥ÐÞ¸´´ËÎó²î¡£
²Î¿¼Á´½Ó£º
https://www.cnvd.org.cn/webinfo/show/5415
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
- Apache Tomcat 6
- Apache Tomcat 7 < 7.0.100
- Apache Tomcat 8 < 8.5.51
- Apache Tomcat 9 < 9.0.31
²»ÊÜÓ°Ïì°æ±¾
- Apache Tomcat = 7.0.100
- Apache Tomcat = 8.5.51
- Apache Tomcat = 9.0.31
Èý¡¢Îó²î¼ì²â
3.1°æ±¾¼ì²â
ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлá°üÀ¨ÓÐÄ¿½ñTomcatµÄ°æ±¾ºÅ£¬Óû§¿Éͨ¹ýÉó²é½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨Ä¿½ñµÄ°æ±¾¡£

ÈôÊǽâѹºóµÄTomcatĿ¼Ãû³Æ±»Ð޻ڸ쬻òÕßͨ¹ýWindows Service Installer·½·¨×°Ö㬿ÉʹÓÃÈí¼þ×Ô´øµÄversionÄ£¿éÀ´»ñȡĿ½ñµÄ°æ±¾¡£½øÈëTomcat×°ÖÃĿ¼µÄbinĿ¼£¬ÊäÈëÏÂÁîversion.batºó£¬¿ÉÉó²éÄ¿½ñµÄÈí¼þ°æ±¾ºÅ¡£

ÈôÄ¿½ñ°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Ôò¿ÉÄܱ£´æÇ徲Σº¦¡£
ËÄ¡¢Îó²î·À»¤
4.1¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
| °æ±¾ºÅ | ÏÂÔØµØµã |
| Apache Tomcat 7.0.100 | http://tomcat.apache.org/download-70.cgi |
| Apache Tomcat 8.5.51 | http://tomcat.apache.org/download-80.cgi |
| Apache Tomcat 9.0.31 | http://tomcat.apache.org/download-90.cgi |
4.2ÆäËû·À»¤²½·¥
ÈôÊÇÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐа汾Éý¼¶£¬¿Éƾ֤×ÔÉíÇéÐνÓÄÉÏÂÁзÀ»¤²½·¥¡£
Ò»:Èô²»ÐèҪʹÓÃTomcat AJPÐÒ飬¿ÉÖ±½Ó¹Ø±ÕAJP Connector£¬»ò½«Æä¼àÌýµØµã¸ÄΪ½ö¼àÌý±¾»úlocalhost¡£
Ïêϸ²Ù×÷£º
£¨1£©±à¼ <CATALINA_BASE>/conf/server.xml£¬ÕÒµ½ÈçÏÂÐУ¨<CATALINA_BASE> Ϊ Tomcat µÄÊÂÇéĿ¼£©£º
<Connector port="8009"protocol="AJP/1.3" redirectPort="8443" />

£¨2£©½«´ËÐÐ×¢Ê͵ô£¨Ò²¿Éɾµô¸ÃÐУ©£º
<!--<Connectorport="8009" protocol="AJP/1.3"redirectPort="8443" />-->
£¨3£©ÉúÑĺóÐèÖØÐÂÆô¶¯Tomcat£¬¹æÔò·½¿ÉÉúЧ¡£
¶þ£ºÈôÐèʹÓÃTomcat AJPÐÒ飬¿Éƾ֤ʹÓð汾ÉèÖÃÐÒéÊôÐÔÉèÖÃÈÏ֤ƾ֤¡£
ʹÓÃTomcat 7ºÍTomcat 9µÄÓû§¿ÉΪAJP ConnectorÉèÖÃsecretÀ´ÉèÖÃAJPÐÒéµÄÈÏ֤ƾ֤¡£ÀýÈç£¨×¢ÖØ±ØÐ轫YOUR_TOMCAT_AJP_SECRET¸ü¸ÄΪһ¸öÇå¾²ÐԸߡ¢ÎÞ·¨±»ÈÝÒײ½âµÄÖµ£©£º
<Connector port="8009"protocol="AJP/1.3" redirectPort="8443"address="YOUR_TOMCAT_IP_ADDRESS" secret="YOUR_TOMCAT_AJP_SECRET"/>
ʹÓÃTomcat 8µÄÓû§¿ÉΪAJP ConnectorÉèÖÃrequiredSecretÀ´ÉèÖÃAJPÐÒéµÄÈÏ֤ƾ֤¡£ÀýÈç£¨×¢ÖØ±ØÐ轫YOUR_TOMCAT_AJP_SECRET¸ü¸ÄΪһ¸öÇå¾²ÐԸߡ¢ÎÞ·¨±»ÈÝÒײ½âµÄÖµ£©£º
<Connector port="8009"protocol="AJP/1.3" redirectPort="8443"address="YOUR_TOMCAT_IP_ADDRESS"requiredSecret="YOUR_TOMCAT_AJP_SECRET" />
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ





