¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©Îó²î
Ðû²¼Ê±¼ä 2025-03-11Apache TomcatÊÇ×ÅÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWebЧÀÍÆ÷£¬£¬£¬£¬£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚÆóÒµ¼¶WebÓ¦Óᣡ£¡£¡£¡£
Ó°Ïì°æ±¾
version < Apache Tomcat 9.0.99
Îó²î³ÉÒò
¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇéÐÎÏ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÌØ¶¨Ä¿Â¼ÏÂдÈëí§ÒâÎļþÃûµÄÎļþ£¬£¬£¬£¬£¬Á¬ÏµTomcatµÄsessionÎļþ´æ´¢¹¦Ð§£¬£¬£¬£¬£¬¿ÉÒÔʵÏÖ·´ÐòÁл¯RCE¡£¡£¡£¡£¡£¸ÃÎó²îʹÓÃÐèÒªÖª×ãÒÔϼ¸¸öÌõ¼þ£º
£¨3£©±£´æ·´ÐòÁл¯Ê¹ÓÃÁ´µÄjar°ü¡£¡£¡£¡£¡£
Îó²î¸´ÏÖ
ÐÞ¸´½¨Òé
Apache¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬£¬£¬£¬Ç뾡¿ìÏÂÔØÇå¾²°æ±¾ÐÞ¸´Îó²î£º
? Apache Tomcat 9.0.99 or later
ʱ¼äÏß
²Î¿¼Á´½Ó£º
[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc