¡¾·ì϶¹«¸æ¡¿Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-24813)
°ä²¼¹¦·ò 2025-03-11Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Apache TomcatÔ¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-24813 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-11 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬ÖØÒªÓÃÓÚÔËÐÐJavaÀûÓ÷¨Ê½£¬³ö¸ñÊÇ»ùÓÚServletºÍJavaServer Pages¼¼ÊõµÄÀûÓá£ËüÓÉApacheÈí¼þ»ù½ð»á¿ª·¢£¬¿í·ºÀûÓÃÓÚWeb¿ª·¢ºÍÆóÒµ¼¶ÀûÓ÷¨Ê½ÖУ¬Ö§³ÖServlet¡¢JavaServer PagesÒÔ¼°WebSocketµÈ¼¼Êõ£¬ÓµÓи߻úÄÜ¡¢¿ÉÀ©´óÐԺͿ¿µÃסÐÔ¡£
2025Äê3ÔÂ11ÈÕ£¬GA»Æ½ð¼×VSRC¼à²âµ½Apache°ä²¼ÁËCVE-2025-24813°²È«²¼¸æ£¬Ö¸³öApache Tomcat´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×¢ÐÅϢй¶»òÊý¾Ý´Û¸Ä¡£¹¥»÷ÕßÔÚÌØ¶¨Ç°ÌáÏ£¨ÈçĬÈÏServletдȨÏÞ¿ªÆô¡¢ÆôÓò¿ÃÅPUTÒªÇ󣩿ÉÉÏ´«Îļþ½Ó¼û°²È«Ãô¸ÐÄÚÈÝ»ò´¥·¢Ô¶³Ì´úÂëÖ´ÐС£¸Ã·ì϶CVSSv3ÆÀ·Ö7.5£¬·ì϶µÈ¼¶Îª¸ßΣ¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://tomcat.apache.org/


¾©¹«Íø°²±¸11010802024551ºÅ