¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©Îó²î

Ðû²¼Ê±¼ä 2025-03-11

Apache TomcatÊÇ×ÅÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWebЧÀÍÆ÷£¬£¬ £¬£¬ £¬£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÓ¦ÓóÌÐò£¬£¬ £¬£¬ £¬£¬ÆÕ±éÓÃÓÚÆóÒµ¼¶WebÓ¦Óᣠ¡£¡£


2025Äê3ÔÂ11ÈÕ£¬£¬ £¬£¬ £¬£¬Tomcat¹Ù·½Ðû²¼ÁËÒ»¸öÇ徲ͨ¸æ£¬£¬ £¬£¬ £¬£¬ÐÞ¸´Ò»¸öÌØ¶¨Ìõ¼þµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-24813£©¡£ ¡£¡£¸ÃÎó²î¿Éµ¼Ö·ÇĬÈÏÉèÖõÄTomcat±»¹¥»÷ÕßʹÓ㬣¬ £¬£¬ £¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´´ËÎó²î¡£ ¡£¡£

Ó°Ïì°æ±¾


version < Apache Tomcat 11.0.3
version < Apache Tomcat 10.1.35

version < Apache Tomcat 9.0.99


Îó²î³ÉÒò


¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇéÐÎÏ£¬£¬ £¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÔÚÌØ¶¨Ä¿Â¼ÏÂдÈëí§ÒâÎļþÃûµÄÎļþ£¬£¬ £¬£¬ £¬£¬Á¬ÏµTomcatµÄsessionÎļþ´æ´¢¹¦Ð§£¬£¬ £¬£¬ £¬£¬¿ÉÒÔʵÏÖ·´ÐòÁл¯RCE¡£ ¡£¡£¸ÃÎó²îʹÓÃÐèÒªÖª×ãÒÔϼ¸¸öÌõ¼þ£º



£¨1£©Ä¬ÈÏservlet¿ªÆôдÈë²Ù×÷¡£ ¡£¡£
£¨2£©Ê¹ÓûùÓÚÎļþ´æ´¢µÄsession£¬£¬ £¬£¬ £¬£¬ÇҴ洢·¾¶Ä¬ÈÏ¡£ ¡£¡£

£¨3£©±£´æ·´ÐòÁл¯Ê¹ÓÃÁ´µÄjar°ü¡£ ¡£¡£


Îó²î¸´ÏÖ


ͼƬ1.png


ÐÞ¸´½¨Òé


Apache¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬ £¬£¬ £¬£¬Ç뾡¿ìÏÂÔØÇå¾²°æ±¾ÐÞ¸´Îó²î£º


? Apache Tomcat 11.0.3 or later
Apache Tomcat 10.1.35 or later

Apache Tomcat 9.0.99 or later


ʱ¼äÏß


2025Äê3ÔÂ11ÈÕ ³§ÉÌÐû²¼Ç徲ͨ¸æ
2025Äê3ÔÂ11ÈÕ ¼øºÚµ£±£ÍøADLab¸´ÏÖÎó²î

²Î¿¼Á´½Ó£º


[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq

[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc