Apache Tomcat HTTP/2¾Ü¾øÐ§ÀÍÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-26Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºcve-2019-0199£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.5£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache Tomcat 8.5.0 ÖÁ 8.5.37
Îó²î¸ÅÊö
Apache Tomcat¹Ù·½Åû¶ÁË¡ª¸öHTTP/2µÄDoSÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îϵHTTP/2ÔÚÎüÊÕ¹ýÁ¿SETTINGS FrameÁ÷Êý¾ÝʱÔÊÐí¿Í»§¶ËÔÚ²»¶Á£¯Ð´ÇëÇó£¯ÏìÓ¦Êý¾ÝµÄÇéÐÎÏÂÈÔÈ»¼á³ÖÁ÷·¿ª×´Ì¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î´Ó¿Í»§¶ËÌᳫ´ó×ÚµÄopen streamÇëÇó´Ó¶øÛÕ±ÕЧÀÍÆ÷¶ËµÄỊ̈߳¬£¬£¬£¬£¬ÒýÆðЧÀÍÆ÷¶ËÏß³Ì×ÊÔ´ºÄ¾¡´Ó¶øµ¼ÖÂЧÀͲ»¿ÉÓᣡ£¡£¡£¡£¡£
Îó²îÑéÖ¤
Éó²éApache Tomcat¶ÔÓ¦µÄ°æ±¾ºÅÊÇ·ñÔÚÊÜÓ°Ïì°æ±¾¹æÄ£ÄÚ¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
http://tomcat.apache.org/security-9.html
http://tomcat.apache.org/security-8.html
²Î¿¼Á´½Ó