CVE-2020-11996 | Apache Tomcat HTTP/2»Ø¾ø·þÎñ·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-29

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-11996

ʱ    ¼ä

2020-06-29

ÀàÐÍ

DOS

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5

Apache Tomcat 9.0.0.M1ÖÁ9.0.35

Apache Tomcat 8.5.0ÖÁ8.5.55


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÀûÓ÷þÎñÆ÷¡£¸Ã·¨Ê½ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö £¬ÊÇ¿ª·¢ºÍµ÷ÊÔJSP ·¨Ê½µÄÊ×Ñ¡¡£ApacheÖ»Ö§³Ö¾²Ì¬ÍøÒ³ £¬µ«Ïñphp,cgi,jspµÈ¶¯Ì¬ÍøÒ³¾Í±ØÒªTomcatÀ´´¦Öá£

2020Äê6ÔÂ25ÈÕ £¬Apache¹Ù·½°ä²¼°²È«²¼¸æ £¬½¨¸´ÁËÒ»¸öApache TomcatÖеÄHTTP/2»Ø¾ø·þÎñ·ì϶£¨CVE-2020-11996£©¡£¸Ã·ì϶ԴÓÚ¶ñÒâµÄHTTP/2ÒªÇóÐòÁпÉÄܻᵼÖ³¤´ï¼¸ÃëÖÓµÄCPU¸ßʹÓÃÂÊ £¬¹¥»÷Õßͨ¹ý·¢ËÍ´óÁ¿µÄ´ËÀàÒªÇóÀ´ÀûÓô˷ì϶ £¬µ¼Ö·þÎñÆ÷»Ø¾øÏìÓ¦ £¬´Ó¶øÊµÏÖDoS¹¥»÷¡£


0x02 ´ëÖý¨Òé


¸Ã·ì϶ӰÏìApache Tomcat 10.0.0-M1ÖÁ10.0.0-M5°æ±¾¡¢9.0.0.M1ÖÁ9.0.35°æ±¾ºÍ8.5.0ÖÁ8.5.55°æ±¾ £¬¹Ù·½ÒѰ䲼×îа汾 £¬ÇëÓйØÓû§ÊµÊ±Éý¼¶ £¬ÏêÇéÈçÏ£º

1. Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5 °æ±¾µÄÓû§ÇëÉý¼¶µ½10.0.0-M6»ò¸ü¸ß°æ±¾ £¬ÏÂÔØµØÖ·£ºhttps://tomcat.apache.org/download-10.cgi

2. Apache Tomcat 9.0.0.M1ÖÁ9.0.35 °æ±¾µÄÓû§ÇëÉý¼¶µ½9.0.36»ò¸ü¸ß°æ±¾ £¬ÏÂÔØµØÖ·£ºhttps://tomcat.apache.org/download-90.cgi

3. Apache Tomcat 8.5.0ÖÁ8.5.55 °æ±¾µÄÓû§ÇëÉý¼¶µ½8.5.56»ò¸ü¸ß°æ±¾ £¬ÏÂÔØµØÖ·£ºhttps://tomcat.apache.org/download-80.cgi


0x03 ÓйØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-11996


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E

http://mail-archives.us.apache.org/mod_mbox/www-announce/202006.mbox/%3Cfd56bc1d-1219-605b-99c7-946bf7bd8ad4%40apache.org%3E


0x05 ¹¦·òÏß


2020-06-25 Apache°ä²¼°²È«²¼¸æ

2020-06-29 VSRC°ä²¼·ì϶¹«¸æ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾