Apache TomcatЧÀÍÆ÷Îļþ°üÀ¨Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-20

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-1938£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache Tomcat 6

Apache Tomcat 7 < 7.0.100

Apache Tomcat 8 < 8.5.51

Apache Tomcat 9 < 9.0.31


Îó²î¸ÅÊö


ApacheÓëTomcat¶¼ÊÇApache¿ªÔ´×éÖ¯¿ª·¢µÄÓÃÓÚ´¦Öóͷ£HTTPЧÀ͵ÄÏîÄ¿£¬£¬£¬£¬£¬£¬£¬Á½Õß¶¼ÊÇÃâ·ÑµÄ£¬£¬£¬£¬£¬£¬£¬¶¼¿ÉÒÔ×öΪ×ÔÁ¦µÄWebЧÀÍÆ÷ÔËÐС£¡£¡£


Apache TomcatЧÀÍÆ÷±£´æÎļþ°üÀ¨Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¶ÁÈ¡»ò°üÀ¨ Tomcat ÉÏËùÓÐ webapp Ŀ¼ÏµÄí§ÒâÎļþ£¬£¬£¬£¬£¬£¬£¬È磺webapp ÉèÖÃÎļþ»òÔ´´úÂëµÈ¡£¡£¡£


¾ÝÆÊÎö£¬£¬£¬£¬£¬£¬£¬Apache Tomcat AJPЭÒé²»Ç徲ȨÏÞ¿ØÖÆ¿Éͨ¹ýAJP ConnectorÖ±½Ó²Ù×÷ÄÚ²¿Êý¾Ý´Ó¶ø´¥·¢Îļþ°üÀ¨Îó²î£¬£¬£¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃЭÒé¶Ë¿Ú£¨Ä¬ÈÏ8009£©Ìá½»¹¥»÷´úÂ룬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÎó²îÄÜ»ñȡĿµÄϵͳÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬»òÔÚ¿ØÖÆ¿ÉÉÏ´«ÎļþµÄÇéÐÎÏÂÖ´ÐжñÒâ´úÂë»ñÈ¡ÖÎÀíȨÏÞ¡£¡£¡£


Îó²îÑéÖ¤


ÒÑÔÚ»¥ÁªÍø¼à²âµ½ÏìÓ¦POC¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒѾ­ÌṩÏà¹ØÎó²î²¹¶¡Á´½Ó£¬£¬£¬£¬£¬£¬£¬Apache Tomcat 7.*·ÖÖ§½¨Òé¸üе½7.0.100°æ±¾£»£»£»£»£»Apache Tomcat 8.*·ÖÖ§½¨Òé¸üе½8.5.51°æ±¾£»£»£»£»£»Apache Tomcat 9.*·ÖÖ§½¨Òé¸üе½9.0.31°æ±¾¡£¡£¡£Apache Tomcat 6 ÒѾ­×èֹά»¤£¬£¬£¬£¬£¬£¬£¬ÇëÉý¼¶µ½×îÐÂÊÜÖ§³ÖµÄ Tomcat °æ±¾ÒÔÃâÔâÊÜÎó²îÓ°Ïì¡£¡£¡£


ÏÂÔØµØµã£º


https://tomcat.apache.org/download-70.cgi

https://tomcat.apache.org/download-80.cgi

https://tomcat.apache.org/download-90.cgi


»òGithubÏÂÔØ£º


https://github.com/apache/tomcat/releases¡£¡£¡£


ÈôÊÇÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐа汾Éý¼¶£¬£¬£¬£¬£¬£¬£¬¿Éƾ֤×ÔÉíÇéÐνÓÄÉÏÂÁзÀ»¤²½·¥¡£¡£¡£


1. ÈçδʹÓÃTomcat AJPЭÒ飺


ÈçδʹÓà Tomcat AJP ЭÒ飬£¬£¬£¬£¬£¬£¬¿ÉÒÔÖ±½Ó½« Tomcat Éý¼¶µ½ 9.0.31¡¢8.5.51»ò 7.0.100 °æ±¾¾ÙÐÐÎó²îÐÞ¸´¡£¡£¡£

ÈçÎÞ·¨Á¬Ã¦¾ÙÐа汾¸üС¢»òÕßÊǸüÀϰ汾µÄÓû§£¬£¬£¬£¬£¬£¬£¬½¨ÒéÖ±½Ó¹Ø±ÕAJPConnector£¬£¬£¬£¬£¬£¬£¬»ò½«Æä¼àÌýµØµã¸ÄΪ½ö¼àÌý±¾»úlocalhost¡£¡£¡£


Ïêϸ²Ù×÷£º


£¨1£©±à¼­ <CATALINA_BASE>/conf/server.xml£¬£¬£¬£¬£¬£¬£¬ÕÒµ½ÈçÏÂÐУ¨<CATALINA_BASE> Ϊ Tomcat µÄÊÂÇéĿ¼£©£º

<Connector port="8009"protocol="AJP/1.3" redirectPort="8443" />

£¨2£©½«´ËÐÐ×¢Ê͵ô£¨Ò²¿Éɾµô¸ÃÐУ©£º

<!--<Connectorport="8009" protocol="AJP/1.3"redirectPort="8443" />-->

£¨3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£


2. ÈôÊÇʹÓÃÁËTomcat AJPЭÒ飺


½¨Ò齫TomcatÁ¬Ã¦Éý¼¶µ½9.0.31¡¢8.5.51»ò7.0.100°æ±¾¾ÙÐÐÐÞ¸´£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÎªAJP ConnectorÉèÖÃsecretÀ´ÉèÖÃAJPЭÒéµÄÈÏ֤ƾ֤¡£¡£¡£ÀýÈç£¨×¢ÖØ±ØÐ轫YOUR_TOMCAT_AJP_SECRET¸ü¸ÄΪһ¸öÇå¾²ÐԸߡ¢ÎÞ·¨±»ÈÝÒײ½âµÄÖµ£©£º


<Connector port="8009"protocol="AJP/1.3" redirectPort="8443"address="YOUR_TOMCAT_IP_ADDRESS" secret="YOUR_TOMCAT_AJP_SECRET"/>


ÈçÎÞ·¨Á¬Ã¦¾ÙÐа汾¸üС¢»òÕßÊǸüÀϰ汾µÄÓû§£¬£¬£¬£¬£¬£¬£¬½¨ÒéΪAJPConnectorÉèÖÃrequiredSecretÀ´ÉèÖÃAJPЭÒéÈÏ֤ƾ֤¡£¡£¡£ÀýÈç£¨×¢ÖØ±ØÐ轫YOUR_TOMCAT_AJP_SECRET¸ü¸ÄΪһ¸öÇå¾²ÐԸߡ¢ÎÞ·¨±»ÈÝÒײ½âµÄÖµ£©£º


<Connector port="8009"protocol="AJP/1.3" redirectPort="8443"address="YOUR_TOMCAT_IP_ADDRESS"requiredSecret="YOUR_TOMCAT_AJP_SECRET" />


²Î¿¼Á´½Ó


https://mp.weixin.qq.com/s/hvRD-0MqXHW8yJupbQt1ng