Apache TomcatÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÀ´Ï®£¨CVE-2025-24813£©£¬ £¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2025-03-13

Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷£¬ £¬£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚÔËÐÐJava WebÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£ËüʵÏÖÁËJava ServletºÍJavaServer PagesÊÖÒÕ£¬ £¬£¬£¬£¬£¬£¬ÌṩÁËÒ»¸öÔËÐÐÇéÐÎÀ´´¦Öóͷ£HTTPÇëÇó¡¢ÌìÉú¶¯Ì¬ÍøÒ³£¬ £¬£¬£¬£¬£¬£¬²¢Ö§³ÖWebSocketͨѶ¡£¡£¡£¡£¡£¡£¡£TomcatÒÔÆäÎȹÌÐÔ¡¢ÎÞаÐÔºÍÒ×ÓÃÐÔ¶øÊܵ½¿ª·¢ÕßµÄÇàíù£¬ £¬£¬£¬£¬£¬£¬ÊÇ¿ª·¢ºÍ°²ÅÅJava WebÓ¦ÓõÄÖ÷Òª¹¤¾ßÖ®Ò»¡£¡£¡£¡£¡£¡£¡£


2025Äê3Ô£¬ £¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼à¿Øµ½Apache¹Ù·½Ðû²¼Îó²îΣº¦Í¨¸æ£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÆôÓÃÁËPartial PUTºÍDefaultServletдÈëȨÏÞµÄÇéÐΣ¬ £¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷ÕßÈÆ¹ý·¾¶Ð£Ñé»á¼ûÃô¸ÐÎļþ»òдÈëÌØ¶¨ÎļþÒÔÖ´ÐжñÒâµÄ·´ÐòÁл¯µ¼Ö´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£


Îó²î±àºÅ

CVE-2025-24813

Îó²îÆÀ¹À

 

Îó²îʹÓÃÄѶÈ

ÖÐ

Îó²îʹÓÃÌõ¼þ

11.0.0-M1 ¡Ü Apache Tomcat ¡Ü 11.0.2

10.1.0-M1 ¡Ü Apache Tomcat ¡Ü 10.1.34

9.0.0.M1 ¡Ü Apache Tomcat ¡Ü 9.0.98

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

¹ûÕæË®Æ½

POCδ¹ûÕæ


Îó²î¸´ÏÖ½ØÍ¼

 

ͼƬ1.png


ͼƬ2.png

 

¼ì²âÒªÁì


½øÈëTomcat×°ÖÃĿ¼µÄbinĿ¼£¬ £¬£¬£¬£¬£¬£¬ÔËÐÐversion.bat£¨LinuxÔËÐÐversion.sh£©ºó£¬ £¬£¬£¬£¬£¬£¬¿ÉÉó²éÄ¿½ñµÄÈí¼þ°æ±¾ºÅ¡£¡£¡£¡£¡£¡£¡£


Ó°Ïì°æ±¾


11.0.0-M1 ¡Ü Apache Tomcat ¡Ü 11.0.2

10.1.0-M1 ¡Ü Apache Tomcat ¡Ü 10.1.34

9.0.0.M1 ¡Ü Apache Tomcat ¡Ü 9.0.98


ÐÞ¸´½¨Òé


1. եȡpartial PUT£ºÔÚ conf/web.xml ÖÐÐÞ¸Ä allowPartialPut ²ÎÊýΪfalse£¬ £¬£¬£¬£¬£¬£¬ÖØÆô Tomcat ÒÔʹÉèÖÃÉúЧ¡£¡£¡£¡£¡£¡£¡£

2. ÑÏ¿á¿ØÖÆ DefaultServlet дÈëȨÏÞ£ºÈ·±£ readonly=true£¬ £¬£¬£¬£¬£¬£¬½ûÓÃËùÓÐδ¾­ÊÚȨµÄ PUT/DELETE ÇëÇó£¬ £¬£¬£¬£¬£¬£¬½öÔÊÔÊÐíÐÅȪԴ»á¼ûÊÜÏÞĿ¼¡£¡£¡£¡£¡£¡£¡£


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®£º


ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾£º

Apache Tomcat >=11.0.3

Apache Tomcat >=10.1.35

Apache Tomcat >=9.0.99


¹Ù·½²¹¶¡ÏÂÔØµØµã£º

https://tomcat.apache.org/security-11.html

https://tomcat.apache.org/security-10.html

https://tomcat.apache.org/security-9.html


¶þ¡¢¼øºÚµ£±£Íø¼Æ»®£º


1¡¢¼øºÚµ£±£Íø¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬ £¬£¬£¬£¬£¬£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦¡£¡£¡£¡£¡£¡£¡£


ÊÂÎñ¿âÏÂÔØµØµã£ºhttps://venustech.download.venuscloud.cn/


2¡¢¼øºÚµ£±£ÍøÂ©É¨²úÆ·¼Æ»®


£¨1£©¡°¼øºÚµ£±£ÍøÎó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£¡£

 

ͼƬ3.png


£¨2£©¼øºÚµ£±£ÍøÎó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£¡£

 

ͼƬ4.png


3¡¢¼øºÚµ£±£Íø×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®


¼øºÚµ£±£Íø×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬¶ÔÈë¿â×ʲúApache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¾ÙÐÐÖÎÀí¡£¡£¡£¡£¡£¡£¡£

 

ͼƬ5.png


4¡¢¼øºÚµ£±£ÍøÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬ £¬£¬£¬£¬£¬£¬¾ÙÐйØÁªÕ½ÂÔÉèÖ㬠£¬£¬£¬£¬£¬£¬Á¬ÏµÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬ £¬£¬£¬£¬£¬£¬´Ó¶ø·¢Ã÷¡°Apache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬ £¬£¬£¬£¬£¬£¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Apache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±Îó²îɨÃèʹÃü£¬ £¬£¬£¬£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£»£»£»£»£»£»£»

 

ͼƬ6.png


2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿£¿£¿éÖУ¬ £¬£¬£¬£¬£¬£¬Ìí¼Ó¡°L2_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±£¬ £¬£¬£¬£¬£¬£¬Í¨¹ý¼øºÚµ£±£Íø¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬ £¬£¬£¬£¬£¬£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º


ͼƬ7.png

 

̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬ £¬£¬£¬£¬£¬£¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓ㻣»£»£»£»£»£»


3£©Ìí¼Ó¡°L3_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±£¬ £¬£¬£¬£¬£¬£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_Apache_TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)¡±£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬ £¬£¬£¬£¬£¬£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬ £¬£¬£¬£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£¡£¡£¡£¡£¡£¡£

 

ͼƬ8.png


4£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


ƾ֤¶ÔApache TomcatÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-24813)µÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬ £¬£¬£¬£¬£¬£¬ÁýÕÖµÄTTP°üÀ¨£º


TA0001-³õʼ»á¼û£ºT1190-ʹÓùûÕæµÄÓ¦ÓÃЧÀÍ

TA0008-ºáÏòÒÆ¶¯£ºT1210-Ô¶³ÌЧÀÍÎó²îʹÓÃ

TA0011-ÏÂÁîÓë¿ØÖÆ£ºT1105-Èë¿Ú¹¤¾ß×ªÒÆ

TA0040-Ó°Ï죺T1485-Êý¾ÝÆÆËð

±í1.jpg

ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬ £¬£¬£¬£¬£¬£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬ £¬£¬£¬£¬£¬£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£


5¡¢¼øºÚµ£±£ÍøÖն˲úÆ·¼Æ»®


Ìì«‘ÖÕ¶ËÇå¾²Ò»Ì廯£¨EDR£©ÌṩÎó²îµÄרÏîÑéÖ¤¼ì²éÄÜÁ¦¿É¶ÔÎó²îפÁôÖն˾ÙÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬ £¬£¬£¬£¬£¬£¬Æ¥ÅäÎó²î×ʲú£¬ £¬£¬£¬£¬£¬£¬Ô¤·ÀÎó²î¹¥»÷Σº¦¡£¡£¡£¡£¡£¡£¡£

 

 Í¼Æ¬9.png