Apache TomcatÔ¶³ÌºÅÁîÖ´Ðзì϶À´Ï®£¨CVE-2025-24813£©£¬£¬£¬OG¶«·½ÌüÌṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2025-03-13Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷£¬£¬£¬¿í·ºÓÃÓÚÔËÐÐJava WebÀûÓ÷¨Ê½¡£¡£ËüʵÏÖÁËJava ServletºÍJavaServer Pages¼¼Êõ£¬£¬£¬ÌṩÁËÒ»¸öÔËÐл·¾³À´´¦ÖÃHTTPÒªÇ󡢡¢¡¢ÌìÉú¶¯Ì¬ÍøÒ³£¬£¬£¬²¢Ö§³ÖWebSocketͨѶ¡£¡£TomcatÒÔÆä²»±äÐÔ¡¢¡¢¡¢½Ã½ÝÐÔºÍÒ×ÓÃÐÔ¶øÊܵ½¿ª·¢ÕßµÄÇàíù£¬£¬£¬ÊÇ¿ª·¢ºÍ²¿ÊðJava WebÀûÓõÄÖØÒª¹¤¾ßÖ®Ò»¡£¡£
2025Äê3Ô£¬£¬£¬OG¶«·½Ìü¼à¿Øµ½Apache¹Ù·½°ä²¼·ì϶·çÏÕ¹«¸æ£¬£¬£¬¸Ã·ì϶ӰÏìÆôÓÃÁËPartial PUTºÍDefaultServletдÈëȨÏ޵Ļ·¾³£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷ÕßÈÆ¹ýõ辶УÑé½Ó¼ûÃô¸ÐÎļþ»òдÈëÌØ¶¨ÎļþÒÔÖ´ÐжñÒâµÄ·´ÐòÁл¯µ¼Ö´úÂëÖ´ÐС£¡£
·ì϶±àºÅ | CVE-2025-24813 | |
·ì϶ÆÀ¹À
| ·ì϶ÀûÓÃÄÑ¶È | ÖÐ |
·ì϶ÀûÓÃǰÌá | 11.0.0-M1 ¡Ü Apache Tomcat ¡Ü 11.0.2 10.1.0-M1 ¡Ü Apache Tomcat ¡Ü 10.1.34 9.0.0.M1 ¡Ü Apache Tomcat ¡Ü 9.0.98 | |
·ì϶ÀàÐÍ | ºÅÁîÖ´ÐÐ | |
¹«¿ªË®Æ½ | POCδ¹«¿ª | |
·ì϶¸´ÏÖ½ØÍ¼


¼ì²â²½Öè
½øÈëTomcat×°ÖÃĿ¼µÄbinĿ¼£¬£¬£¬ÔËÐÐversion.bat£¨LinuxÔËÐÐversion.sh£©ºó£¬£¬£¬¿É²é¿´µ±Ç°µÄÈí¼þ°æ±¾ºÅ¡£¡£
Ó°Ïì°æ±¾
11.0.0-M1 ¡Ü Apache Tomcat ¡Ü 11.0.2
10.1.0-M1 ¡Ü Apache Tomcat ¡Ü 10.1.34
9.0.0.M1 ¡Ü Apache Tomcat ¡Ü 9.0.98
ÐÞ¸´½¨Òé
1. ²»ÈÝpartial PUT£ºÔÚ conf/web.xml ÖÐÅú¸Ä allowPartialPut ²ÎÊýΪfalse£¬£¬£¬ÖØÆô Tomcat ÒÔʹÅäÖÃÉúЧ¡£¡£
2. Ñϸñ½ÚÖÆ DefaultServlet дÈëȨÏÞ£ºÈ·±£ readonly=true£¬£¬£¬½ûÓÃËùÓÐδ¾ÊÚȨµÄ PUT/DELETE ÒªÇ󣬣¬£¬½öÔÊÐí¿ÉÐÅÆðÔ´½Ó¼ûÊÜÏÞĿ¼¡£¡£
Ò»¡¢¡¢¡¢¹Ù·½ÐÞ¸´¹æ»®£º
Ŀǰ¹Ù·½ÒѰ䲼°²È«¸üУ¬£¬£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾£º
Apache Tomcat >=11.0.3
Apache Tomcat >=10.1.35
Apache Tomcat >=9.0.99
¹Ù·½²¹¶¡ÏÂÔØµØÖ·£º
https://tomcat.apache.org/security-11.html
https://tomcat.apache.org/security-10.html
https://tomcat.apache.org/security-9.html
¶þ¡¢¡¢¡¢OG¶«·½Ìü¹æ»®£º
1¡¢¡¢¡¢OG¶«·½Ìü¼ì²âÀà²úÆ·¹æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢¡¢¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢¡¢¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢¡¢¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢¡¢¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬£¬£¬Éý¼¶µ½×îа汾¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£¡£
ÊÂÎñ¿âÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/
2¡¢¡¢¡¢OG¶«·½Ìü©ɨ²úÆ·¹æ»®
£¨1£©¡°OG¶«·½Ìü·ì϶ɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£

£¨2£©OG¶«·½Ìü·ì϶ɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£

3¡¢¡¢¡¢OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®
OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬£¬¶ÔÈë¿â×ʲúApache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)½øÐÐÖÎÀí¡£¡£

4¡¢¡¢¡¢OG¶«·½Ìü°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®
Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬£¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬£¬´Ó¶ø·¢ÏÖ¡°Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£¡£
1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)¡±·ì϶ɨÃ蹤×÷£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú£»

2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬£¬£¬Ôö³¤¡°L2_Apache_TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)¡±£¬£¬£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢¡¢¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_Apache_TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓã»
3£©Ôö³¤¡°L3_Apache_TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)¡±£¬£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_Apache_TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)¡±£¬£¬£¬¹¥»÷Á˾ֵÈÓÚ¡°¹¥»÷³É¹¦¡±£¬£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£¡£

4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé
ƾ¾Ý¶ÔApache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬£¬£¬¸²¸ÇµÄTTPÔ̺¬£º
TA0001-³õʼ½Ó¼û£ºT1190-ÀûÓù«¿ªµÄÀûÓ÷þÎñ
TA0008-ºáÏòÒÆ¶¯£ºT1210-Ô¶³Ì·þÎñ·ì϶ÀûÓÃ
TA0011-ºÅÁîÓë½ÚÖÆ£ºT1105-Èë¿Ú¹¤¾ß×ªÒÆ
TA0040-Ó°Ï죺T1485-Êý¾Ý·ÛËé

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬£¬£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬£¬½øÐÐ×Ô¶¯»¯´ëÖᣡ£
5¡¢¡¢¡¢OG¶«·½ÌüÖն˲úÆ·¹æ»®
Ìì«‘Öն˰²È«Ò»Ì廯£¨EDR£©Ìṩ·ì϶µÄרÏîÑéÖ¤²é³ÄÜÁ¦¿É¶Ô·ì϶פÁôÖն˽øÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬£¬£¬Æ¥Åä·ì϶×ʲú£¬£¬£¬Ô¤·À·ì϶¹¥»÷·çÏÕ¡£¡£



¾©¹«Íø°²±¸11010802024551ºÅ