Apache TomcatÇå¾²Îó²îÖÒÑÔ
Ðû²¼Ê±¼ä 2018-07-25Îó²î±àºÅºÍ¼¶±ð
CVE-2018-8034 ³§ÉÌ×ÔÆÀ£ºµÍ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-8037 ³§ÉÌ×ÔÆÀ£ºÖ÷Òª CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1336 ³§ÉÌ×ÔÆÀ£ºÖ÷Òª CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Îó²î¸ÅÊö
Apache TomcatÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬°üÀ¨¿Éµ¼ÖÂÐÅϢй¶µÄÎó²î£¨CVE-2018-8037£©¡¢¿Éµ¼Ö¾ܾøÐ§À͵ÄÎó²î£¨CVE-2018-1336£©ÒÔ¼°Çå¾²ÈÆ¹ýÎó²î£¨CVE-2018-8034£©¡£¡£¡£¡£¡£¡£ÏÖÔÚûÓз¢Ã÷ÈκÎʹÓÃÕâЩÎó²îµÄÊÂÎñ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£¡£¡£¡£¡£¡£
CVE-2018-8034
Ôµ¹ÊÔÓÉÔÚÓÚWebSocket¿Í»§¶ËʹÓÃTLSʱȱÉÙÖ÷»úÃûÑéÖ¤£¬£¬£¬£¬£¬£¬²¢ÇÒÊÇĬÈÏÆôÓõġ£¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º
Apache Tomcat 9.0.0.M1 to 9.0.9
Apache Tomcat 8.5.0 to 8.5.31
Apache Tomcat 8.0.0.RC1 to 8.0.52
Apache Tomcat 7.0.35 to 7.0.88
ÐÞ¸´½¨Ò飺
Éý¼¶ÖÁApache Tomcat 9.0.10 or later
Éý¼¶ÖÁApache Tomcat 8.5.32 or later
Éý¼¶ÖÁApache Tomcat 8.0.53 or later
Éý¼¶ÖÁApache Tomcat 7.0.90 or later
CVE-2018-8037
Ôµ¹ÊÔÓÉÔÚÓÚ¸ú×ÙÅþÁ¬¹Ø±ÕʱµÄ¹ýʧµ¼ÖÂÔÚÐÂÅþÁ¬ÖÐÖØÓÃÓû§»á»°¡£¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º
Apache Tomcat 9.0.0.M9 to 9.0.9
Apache Tomcat 8.5.5 to 8.5.31
ÐÞ¸´½¨Ò飺
Éý¼¶ÖÁApache Tomcat 9.0.10 or later
Éý¼¶ÖÁApache Tomcat 8.5.32 or later
CVE-2018-1336
Ôµ¹ÊÔÓÉÔÚÓÚÔÚ¾ßÓÐÔö²¹×Ö·ûµÄUTF-8½âÂëÆ÷Öв»×¼È·µØ´¦Öóͷ£Òç³ö¿ÉÄܵ¼Ö½âÂëÆ÷ÖеÄÎÞÏÞÑ»·µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º
Apache Tomcat 9.0.0.M9 to 9.0.7
Apache Tomcat 8.5.0 to 8.5.30
Apache Tomcat 8.0.0.RC1 to 8.0.51
Apache Tomcat 7.0.28 to 7.0.86
ÐÞ¸´½¨Ò飺
Éý¼¶ÖÁApache Tomcat 9.0.7 or later
Éý¼¶ÖÁApache Tomcat 8.5.32 or later
Éý¼¶ÖÁApache Tomcat 8.0.52 or later
Éý¼¶ÖÁApache Tomcat 7.0.90 or later
ÐÞ¸´½¨Òé
ASF¹Ù·½²¼¸üв¹¶¡£¡£¡£¡£¡£¡£ºhttp://tomcat.apache.org/security-9.html£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
http://tomcat.apache.org/security-9.html
https://thehackernews.com/2018/07/apache-tomcat-server.html