Apache Tomcat HTTP/2»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-26·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºcve-2019-0199£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.5£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache Tomcat 8.5.0 ÖÁ 8.5.37
·ì϶¸ÅÊö
Apache Tomcat¹Ù·½Åû¶ÁË¡ª¸öHTTP/2µÄDoS·ì϶£¬¸Ã·ì϶ϵHTTP/2ÔڽӹܹýÁ¿SETTINGS FrameÁ÷Êý¾ÝʱÔÊÐí¿Í»§¶ËÔÚ²»¶Á£¯Ð´ÒªÇó£¯ÏìÓ¦Êý¾ÝµÄÇé¿öÏÂÒÀȻά³ÖÁ÷´ò¿ª×´Ì¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶´Ó¿Í»§¶ËÌáÒé´óÁ¿µÄopen streamÒªÇó´Ó¶ø×èÈû·þÎñÆ÷¶ËµÄỊ̈߳¬ÒýÆð·þÎñÆ÷¶ËÏß³Ì×ÊÔ´ºÄ¾¡´Ó¶øµ¼Ö·þÎñ²»³ÉÓá£
·ì϶ÑéÖ¤
²é¿´Apache Tomcat¶ÔÓ¦µÄ°æ±¾ºÅÊÇ·ñÔÚÊÜÓ°Ïì°æ¼¼ÇÉÓòÄÚ¡£
½¨¸´½¨Òé
http://tomcat.apache.org/security-9.html
http://tomcat.apache.org/security-8.html
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ