¡¾·À»¤¼Æ»®¡¿Apache TomcatÎļþ°üÀ¨Îó²î(CVE-2020-1938)
2020-02-20
Ò»¡¢×ÛÊö
2ÔÂ20ÈÕ£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©Ðû²¼ÁËÒ»Ôò¹ØÓÚApache Tomcat±£´æÎļþ°üÀ¨Îó²îµÄÇ徲ͨ¸æ¡£
ͨ¸æÖÐÌåÏÖ£¬±£´æÓÚApache TomcatÖеÄÎļþ°üÀ¨Îó²î£¨CNVD-2020-10487£¬¶ÔÓ¦CVE-2020-1938£©¿Éʹ¹¥»÷ÕßÔÚδÊÚȨµÄÇéÐÎÏÂÔ¶³Ì¶ÁÈ¡ÌØ¶¨Ä¿Â¼ÏµÄí§ÒâÎļþ¡£
Îó²îÔ´ÓÚTomcat AJPÐÒéʵÏÖÖеÄȱÏÝ£¬Ê¹µÃÏà¹Ø²ÎÊý¿É¿Ø¡£Í¨¹ýÏòAJPÐÒé¶Ë¿Ú£¨Ä¬ÈÏ8009£©·¢ËÍÈ«ÐĽṹµÄÊý¾Ý£¬¿É¶ÁÈ¡·þÎñÆ÷webappĿ¼ÏµÄí§ÒâÎļþ£¬ºÃ±ÈÉèÖÃÎļþ¡¢Ô´´úÂëµÈ¡£²¢ÇÒÈôÊÇ·þÎñÆ÷¶ËÓÐÎļþÉÏ´«¹¦Ð§£¬ÄÇô»¹¿ÉÄܽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëµÄÖ´ÐС£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÑÔÚµÚһʱ¼ä¸´ÏÖÁËʹÓøÃÎó²î¶ÁÈ¡ÎļþµÄÀú³Ì£¬Ð§¹ûÈçÏÂͼËùʾ:

±ðµÄ£¬ÔÚ·þÎñÆ÷Éϱ£´æÉÏ´«µãµÄÇéÐÎÏ£¬¸´ÏÖÁËÔ¶³Ì´úÂëÖ´ÐС£

²Î¿¼Á´½Ó£º
https://www.cnvd.org.cn/webinfo/show/5415
¶þ¡¢Îó²îÓ°Ïì¹æÄ£
- Tomcat 6 (ÒѲ»ÊÜά»¤)
- Tomcat 7 Version < 7.0.100
- Tomcat 8 Version < 8.5.51
- Tomcat 9 Version < 9.0.31
Èý¡¢Ó°ÏìÅŲé
3.1 ÍâµØ¼ì²â
ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлá°üÀ¨ÓÐÄ¿½ñTomcatµÄ°æ±¾ºÅ£¬Óû§¿Éͨ¹ýÉó²é½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨Ä¿½ñµÄ°æ±¾¡£

ÈôÊǽâѹºóµÄTomcatĿ¼Ãû³Æ±»Ð޻ڸ쬻òÕßͨ¹ýWindows Service Installer·½·¨×°Ö㬿ÉʹÓÃÈí¼þ×Ô´øµÄversionÄ£¿éÀ´»ñȡĿ½ñµÄ°æ±¾¡£½øÈëTomcat×°ÖÃĿ¼µÄbinĿ¼£¬ÊäÈëÏÂÁîversion.batºó£¬¿ÉÉó²éÄ¿½ñµÄÈí¼þ°æ±¾ºÅ¡£

ÈôÄ¿½ñ°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Ôò¿ÉÄܱ£´æÇ徲Σº¦¡£
ËÄ¡¢ÊÖÒÕ·À»¤¼Æ»®
4.1 ¹Ù·½ÐÞ¸´¼Æ»®
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
Apache Tomcat 7.0.100 £ºhttp://tomcat.apache.org/download-70.cgi
Apache Tomcat 8.5.51 £ºhttp://tomcat.apache.org/download-80.cgi
Apache Tomcat 9.0.31 £ºhttp://tomcat.apache.org/download-90.cgi
4.2 ÔÝʱ½â¾ö¼Æ»®
ÈôÊÇÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐа汾Éý¼¶£¬¿Éƾ֤×ÔÉíÇéÐνÓÄÉÏÂÁзÀ»¤²½·¥¡£
- Èô²»ÐèҪʹÓÃTomcat AJPÐÒ飬¿ÉÖ±½Ó¹Ø±ÕAJP Connector£¬»ò½«Æä¼àÌýµØµã¸ÄΪ½ö¼àÌý±¾»úlocalhost¡£Ïêϸ²Ù×÷£º
£¨1£©±à¼ <CATALINA_BASE>/conf/server.xml£¬ÕÒµ½ÈçÏÂÐУ¨<CATALINA_BASE> Ϊ Tomcat µÄÊÂÇéĿ¼£©£º

£¨2£©½«´ËÐÐ×¢Ê͵ô£¨Ò²¿Éɾµô¸ÃÐУ©£º
<!--<Connectorport="8009" protocol="AJP/1.3"redirectPort="8443" />--> |
£¨3£©ÉúÑĺóÐèÖØÐÂÆô¶¯Tomcat£¬¹æÔò·½¿ÉÉúЧ¡£
- ÈôÐèʹÓÃTomcat AJPÐÒ飬¿Éƾ֤ʹÓð汾ÉèÖÃÐÒéÊôÐÔÉèÖÃÈÏ֤ƾ֤¡£
ʹÓÃTomcat 7ºÍTomcat 9µÄÓû§¿ÉΪAJP ConnectorÉèÖÃsecretÀ´ÉèÖÃAJPÐÒéµÄÈÏ֤ƾ֤¡£ÀýÈç£¨×¢ÖØ±ØÐ轫YOUR_TOMCAT_AJP_SECRET¸ü¸ÄΪһ¸öÇå¾²ÐԸߡ¢ÎÞ·¨±»ÈÝÒײ½âµÄÖµ£©£º
<Connector port="8009"protocol="AJP/1.3" redirectPort="8443"address="YOUR_TO MCAT_IP_ADDRESS" secret="YOUR_TOMCAT_AJP_SECRET"/> |
ʹÓÃTomcat 8µÄÓû§¿ÉΪAJP ConnectorÉèÖÃrequiredSecretÀ´ÉèÖÃAJPÐÒéµÄÈÏ֤ƾ֤¡£ÀýÈç£¨×¢ÖØ±ØÐ轫YOUR_TOMCAT_AJP_SECRET¸ü¸ÄΪһ¸öÇå¾²ÐԸߡ¢ÎÞ·¨±»ÈÝÒײ½âµÄÖµ£©£º
<Connector port="8009"protocol="AJP/1.3" redirectPort="8443"address="YOUR_TO MCAT_IP_ADDRESS"requiredSecret="YOUR_TOMCAT_AJP_SECRET" /> |
4.3 ¾ÅÓÎÀÏ¸ç¿Æ¼¼¼ì²â·À»¤½¨Òé
4.3.1 ¾ÅÓÎÀÏ¸ç¿Æ¼¼¼ì²âÀà²úÆ·Óë·þÎñ
1¡¢×ʲú¿ÉʹÓþÅÓÎÀϸçÔÆ½ôÆÈÎó²îÔÚÏß¼ì²â£¬¼ì²âµØµãÈçÏ£º
ÊÖ»ú¶Ë»á¿´·¨Ö·£º
https://cloud.nsfocus.com/megi/holes/hole_ApacheTomcat_2020_02_20.html
PC¶Ë»á¿´·¨Ö·£ºhttps://cloud.nsfocus.com/#/krosa/views/initcdr/productandservice?service_id=1026
2¡¢ÄÚÍø×ʲú¿ÉÒÔʹÓþÅÓÎÀÏ¸ç¿Æ¼¼µÄÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©¡¢WebÓ¦ÓÃÎó²îɨÃèϵͳ£¨WVSS£©¡¢ÈëÇÖ¼ì²âϵͳ(IDS)¡¢Í³Ò»Íþв̽Õ루UTS£©¾ÙÐмì²â¡£
- Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©ÏµÍ³²å¼þ
http://update.nsfocus.com/update/listRsasDetail/v/vulsys
- Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©Web²å¼þ
http://update.nsfocus.com/update/listRsasDetail/v/vulweb
- WebÓ¦ÓÃÎó²îɨÃèϵͳ£¨WVSS£©
http://update.nsfocus.com/update/listWvssDetail/v/6/t/plg
- ÈëÇÖ¼ì²âϵͳ£¨IDS£©
http://update.nsfocus.com/update/listIds
http://update.nsfocus.com/update/listBsaUtsDetail/v/rule2.0.0
ͨ¹ýÉÏÊöÁ´½Ó£¬Éý¼¶ÖÁ×îа汾¼´¿É¾ÙÐмì²â£¡
4.3.2 ʹÓþÅÓÎÀÏ¸ç¿Æ¼¼·À»¤Àà²úÆ·¾ÙÐзÀ»¤
ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©
http://update.nsfocus.com/update/listIps
ͨ¹ýÉÏÊöÁ´½Ó£¬Éý¼¶ÖÁ×îа汾¼´¿É¾ÙÐзÀ»¤£¡
4.3.3 ¼ì²â·À»¤²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ
| ¼ì²â²úÆ· | Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
| RSAS V6 ϵͳ²å¼þ°ü | V6.0R02F01.1709 |
| RSAS V6 Web²å¼þ°ü | V6.0R02F00.1604 |
| WVSSV6 ²å¼þ°ü | V6.0R03F00.153 |
| IDS | 5.6.8.816¡¢ 5.6.9.21979¡¢ 5.6.10.21979 |
| UTS | 5.6.10.21979 |
×¢ÖØ£ºIDPS 569/5610ºÍUTS×°±¸£¬Òª¼ì²â¸ÃÎó²î£¬ÐèÒª½«×¨Òµ²ÎÊýµÄUnknownDisableEncrypt¿ª¹ØÖÃΪ·ñ¡£
- RSAS V6 ϵͳ²å¼þ°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/102566
- RSAS V6 Web²å¼þ°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/102580
- WVSSV6²å¼þ°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/102537
- IDS Éý¼¶°üÏÂÔØÁ´½Ó£º
5.6.8.816
http://update.nsfocus.com/update/downloads/id/102567
5.6.9.21979
http://update.nsfocus.com/update/downloads/id/102575
5.6.10.21979
http://update.nsfocus.com/update/downloads/id/102576
- UTS Éý¼¶°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/102579
| ·À»¤²úÆ· | Éý¼¶°ü/¹æÔò°æ±¾ºÅ | ¹æÔò±àºÅ |
| IPS | 5.6.8.816¡¢ 5.6.9.21979¡¢ 5.6.10.21979 | 24719 |
- IPS Éý¼¶°üÏÂÔØÁ´½Ó£º
5.6.8.816
http://update.nsfocus.com/update/downloads/id/102567
5.6.9.21979
http://update.nsfocus.com/update/downloads/id/102575
5.6.10.21979
http://update.nsfocus.com/update/downloads/id/102576
4.3.4 Ç徲ƽ̨
| ƽ̨ | Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
| ESP£¨¾ÅÓÎÀϸçÆóÒµÇ徲ƽ̨½â¾ö¼Æ»®£© | ʹÓùæÔòÉý¼¶°üÉý¼¶£º ESP-EVENTRULE-004-20200221.dat |
| ESP-H£¨¾ÅÓÎÀϸçÆóÒµÇ徲ƽ̨£© | ʹÓùæÔòÉý¼¶°üÉý¼¶£º ESP-EVENTRULE-003-20200221.dat »òÕßESP-EVENTRULE-004-20200221.dat |
| ISOP£¨¾ÅÓÎÀϸçÖÇÄÜÇå¾²ÔËӪƽ̨£© | ʹÓùæÔòÉý¼¶°üÉý¼¶£º attack_rule.1.0.0.0.204825.dat |
| TVM£¨¾ÅÓÎÀϸçÍþвºÍÎó²îÇå¾²ÖÎÀíÆ½Ì¨£© | 2020022101 |
| BSA£¨¾ÅÓÎÀϸçÈÕÖ¾Êý¾ÝÇå¾²ÐÔÆÊÎöϵͳ£© | 2.0R00F05SP03 2.0R01F00SP03 |
Îå¡¢¸½Â¼A ·²úƷʹÓÃÖ¸ÄÏ
$(".info_chag img").each(function () { $(this).css({ "max-width": "100%","height": "auto","display":"inline-block" }).parent().css({"text-align":"center"}); });
ÄúµÄÁªÏµ·½·¨
? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

¾ÅÓÎÀϸçÔÆ





