¡¾·ì϶¹«¸æ¡¿CVE-2021-24122 Apache TomcatÐÅϢй¶·ì϶
°ä²¼¹¦·ò 2021-01-150x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-24122 | ʱ ¼ä | 2021-01-15 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé



Ó°ÏìÁìÓò
Apache Tomcat 10.0.0-M1-10.0.0-M9
Apache Tomcat 9.0.0.M1-9.0.39
Apache Tomcat 8.5.0-8.5.59
Apache Tomcat 7.0.0-7.0.106
0x02 ´ëÖý¨Òé
ĿǰTomcatÒѾ½¨¸´ÁË´Ë·ì϶£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º
Apache Tomcat 10.0.0-M10»ò¸ü¸ß°æ±¾
Apache Tomcat 9.0.40»ò¸ü¸ß°æ±¾
Apache Tomcat 8.5.60»ò¸ü¸ß°æ±¾
Apache Tomcat 7.0.107»ò¸ü¸ß°æ±¾
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/
0x03 ²Î¿¼Á´½Ó
https://tomcat.apache.org/security-10.html
http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3Cf3765f21-969d-7f21-e34a-efc106175373@apache.org%3E
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24122
0x04 ¹¦·òÏß
2021-01-14 Apache°ä²¼°²È«²¼¸æ
2021-01-15 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ