¡¾·ì϶¹«¸æ¡¿Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)
°ä²¼¹¦·ò 2025-03-11Ò»¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-24813 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-11 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬£¬ÖØÒªÓÃÓÚÔËÐÐJavaÀûÓ÷¨Ê½£¬£¬³ö¸ñÊÇ»ùÓÚServletºÍJavaServer Pages¼¼ÊõµÄÀûÓᣡ£ËüÓÉApacheÈí¼þ»ù½ð»á¿ª·¢£¬£¬¿í·ºÀûÓÃÓÚWeb¿ª·¢ºÍÆóÒµ¼¶ÀûÓ÷¨Ê½ÖУ¬£¬Ö§³ÖServlet¡¢JavaServer PagesÒÔ¼°WebSocketµÈ¼¼Êõ£¬£¬ÓµÓи߻úÄÜ¡¢¿ÉÀ©´óÐԺͿ¿µÃסÐÔ¡£¡£
2025Äê3ÔÂ11ÈÕ£¬£¬OG¶«·½ÌüVSRC¼à²âµ½Apache°ä²¼ÁËCVE-2025-24813°²È«²¼¸æ£¬£¬Ö¸³öApache Tomcat´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС¢ÐÅϢй¶»òÊý¾Ý´Û¸Ä¡£¡£¹¥»÷ÕßÔÚÌØ¶¨Ç°ÌáÏ£¨ÈçĬÈÏServletдȨÏÞ¿ªÆô¡¢ÆôÓò¿ÃÅPUTÒªÇ󣩿ÉÉÏ´«Îļþ½Ó¼û°²È«Ãô¸ÐÄÚÈÝ»ò´¥·¢Ô¶³Ì´úÂëÖ´ÐС£¡£¸Ã·ì϶CVSSv3ÆÀ·Ö7.5£¬£¬·ì϶µÈ¼¶Îª¸ßΣ¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://tomcat.apache.org/


¾©¹«Íø°²±¸11010802024551ºÅ