Apache Tomcat h2cÒªÇó»ìºÏ·ì϶£¨CVE-2021-25122£©

°ä²¼¹¦·ò 2021-03-02

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-25122

ʱ   ¼ä

2021-03-02

Àà   ÐÍ


µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê03ÔÂ01ÈÕ£¬Apache¹Ù·½°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËTomcatÖеÄÒ»¸ö h2cÒªÇó»ìºÏ·ì϶£¨CVE-2021-25122£©¡£

µ±ÏìӦеÄh2cÏνÓÒªÇóʱ£¬Apache TomcatÄܹ»½«ÒªÇó±êÍ·ºÍÊýÁ¿ÓÐÏÞµÄÒªÇóÖ÷Ìå´ÓÒ»¸öÒªÇó¸´Ôìµ½ÁíÒ»¸öÒªÇó£¬Õ⽫µ¼ÖÂÓû§AºÍÓû§B¶¼Äܹ»¿´µ½Óû§AµÄÒªÇóÁ˾Ö¡£Ä¿Ç°¸Ã·ì϶ÒѾ­½¨¸´£¬´úÂëÈçÏ£º

image.png

 

Ó°ÏìÁìÓò

Apache Tomcat 10.0.0-M1-10.0.0

Apache Tomcat 9.0.0.M1-9.0.41

Apache Tomcat 8.5.0-8.5.61

 

´Ë±í£¬ÓÉÓÚApache Tomcat¶ÔCVE-2020-9484µÄ½¨¸´²»ÆëÈ«£¬µ¼ÖÂTomcatÒÀÈ»ÈÝÒ×Êܵ½Õë¶ÔCVE-2020-9484µÄ¹¥»÷£¨·ì϶׷×ÙΪCVE-2021-25329£¬µÍΣ£©¡£¸Ã·ì϶½«Ó°ÏìApache Tomcat°æ±¾10.0.0-M1-10.0.0¡¢9.0.0.M1-9.0.41¡¢8.5.0-8.5.61¡¢7.0.0-7.0.107£¬CVE-2020-9484µÄÀûÓÃǰÌá¼°»º½â´ëʩͬÑùºÏÓÃÓÚ´Ë·ì϶¡£

 

0x02 ´ëÖý¨Òé

Õë¶ÔCVE-2021-25122£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

Apache Tomcat 10.0.2»ò¸ü¸ß°æ±¾¡£

Apache Tomcat 9.0.43»ò¸ü¸ß°æ±¾¡£

Apache Tomcat 8.5.63»ò¸ü¸ß°æ±¾¡£

 

Õë¶ÔCVE-2021-25329£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

Apache Tomcat 10.0.2»ò¸ü¸ß°æ±¾¡£

Apache Tomcat 9.0.43»ò¸ü¸ß°æ±¾¡£

Apache Tomcat 8.5.63»ò¸ü¸ß°æ±¾¡£

Apache Tomcat 7.0.108»ò¸ü¸ß°æ±¾¡£

 

ÏÂÔØÁ´½Ó£º

https://tomcat.apache.org/download-10.cgi

 

0x03 ²Î¿¼Á´½Ó

https://tomcat.apache.org/security-10.html

http://mail-archives.apache.org/mod_mbox/www-announce/202103.mbox/%3Cb7626398-5e6d-1639-4e9e-e41b34af84de@apache.org%3E

http://mail-archives.apache.org/mod_mbox/www-announce/202103.mbox/%3C811bba77-e74e-9f9b-62ca-5253a09ba84f@apache.org%3E

https://github.com/apache/tomcat/commit/dd757c0a893e2e35f8bc1385d6967221ae8b9b9b#

 

0x04 ¹¦·òÏß

2021-03-01  Apache°ä²¼°²È«²¼¸æ

2021-03-02  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png