¡¾Îó²îͨ¸æ¡¿Apache TomcatÇëÇó×ß˽Îó²î£¨CVE-2023-45648£©
Ðû²¼Ê±¼ä 2023-10-11Ò»¡¢Îó²î¸ÅÊö
CVE ID | CVE-2023-45648 | ·¢Ã÷ʱ¼ä | 2023-10-11 |
Àà ÐÍ | HTTPÇëÇó×ß˽ | µÈ ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÖØÆ¯ºó | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache TomcatÊÇÒ»¸öÊ¢ÐеĿªÔ´WebЧÀÍÆ÷ºÍJava ServletÈÝÆ÷¡£¡£¡£
10ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøVSRC¼à²âµ½Apache TomcatÖÐÐÞ¸´ÁËÒ»¸öÇëÇó×ß˽Îó²î£¨CVE-2023-45648£©£¬£¬£¬£¬£¬£¬ÓÉÓÚTomcatδÄÜ׼ȷÆÊÎöHTTP Trailer±êÍ·£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÌØÖÆµÄÎÞЧTrailer±êÍ·µ¼ÖÂTomcat ½«µ¥¸öÇëÇóÊÓΪ¶à¸öÇëÇ󣬣¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔÚ·´ÏòÊðÀíÖ®ºó·ºÆðÇëÇó×ß˽¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÈÆ¹ýÇå¾²¿ØÖÆ£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨ»á¼ûÃô¸ÐÊý¾ÝµÈ¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬TomcatÖл¹ÐÞ¸´ÁËÒÔÏÂ3¸öÎó²î£º
CVE-2023-44487£ºTomcat HTTP/2 ¿ìËÙÖØÖù¥»÷¾Ü¾øÐ§ÀÍÎó²î£¨¸ßΣ£©
Tomcat µÄ HTTP/2 ʵÏÖÈÝÒ×Êܵ½¿ìËÙÖØÖù¥»÷Îó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö·ºÆðOutOfMemoryError²¢¿ÉÄÜÔì³É¾Ü¾øÐ§ÀÍ¡£¡£¡£
CVE-2023-42795£ºTomcatÐÅϢй¶Îó²î£¨¸ßΣ£©
Tomcat¶à¸öÊÜÓ°Ïì°æ±¾ÖУ¬£¬£¬£¬£¬£¬µ±½ÓÄÉÖÖÖÖÄÚ²¿¹¤¾ß£¨°üÀ¨ÇëÇóºÍÏìÓ¦£©Ê±£¬£¬£¬£¬£¬£¬ÔÚÏÂÒ»¸öÇëÇó/ÏìÓ¦ÖØÐÂʹÓÃ֮ǰ£¬£¬£¬£¬£¬£¬¿ÉÄÜ·ºÆð¹ýʧµ¼ÖÂTomcat Ìø¹ý½ÓÄÉÀú³ÌµÄijЩ²¿·Ö£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÐÅÏ¢´ÓÄ¿½ñÇëÇó/ÏìӦй¶µ½ÏÂÒ»¸ö¡£¡£¡£
CVE-2023-42794 £ºApache Tomcat¾Ü¾øÐ§ÀÍÎó²î£¨µÍΣ£©
TomcatµÄCommons FileUploadÄÚ²¿·ÖÖ§°üÀ¨Ò»¸öδÐû²¼µÄ¡¢ÕýÔÚ¾ÙÐеÄÖØ¹¹£¬£¬£¬£¬£¬£¬ÈôÊÇwebÓ¦ÓóÌÐòΪÉÏ´«µÄÎļþ·¿ªÁËÒ»¸öÁ÷£¬£¬£¬£¬£¬£¬µ«Î´ÄܹرոÃÁ÷£¬£¬£¬£¬£¬£¬Ôò¿ÉÄÜÔÚWindowsÉϵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¸ÃÎļþÓÀÔ¶²»»á´Ó´ÅÅÌÖÐɾ³ý£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄÜÒò´ÅÅÌÒÑÂú¶ø×îÖÕµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
CVE-2023-45648¡¢CVE-2023-44487¡¢CVE-2023-42795
Apache Tomcat 11.0.0-M1 - 11.0.0-M11
Apache Tomcat 10.1.0-M1 - 10.1.13
Apache Tomcat 9.0.0-M1 - 9.0.80
Apache Tomcat 8.5.0 - 8.5.93
CVE-2023-42794
Apache Tomcat 9.0.70 - 9.0.80
Apache Tomcat 8.5.85 - 8.5.93
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
CVE-2023-45648¡¢CVE-2023-44487¡¢CVE-2023-42795
Apache Tomcat >=11.0.0-M12
Apache Tomcat >= 10.1.14
Apache Tomcat >= 9.0.81
Apache Tomcat >= 8.5.94
CVE-2023-42794
Apache Tomcat >= 9.0.81
Apache Tomcat >= 8.5.94
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp
https://lists.apache.org/thread/065jfyo583490r9j2v73nhpyxdob56lw
https://lists.apache.org/thread/vvbr2ms7lockj1hlhz5q3wmxb2mwcw82
https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-10-11 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£
5.2 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º