ʵս³öÕæÖª | °²ÐÇÖÇÄÜÌ帳ÄÜʵս»¯ÔËÓª£¬£¬£¬ £¬£¬¸ßЧӦ¶Ô¸ßΣÎó²î

Ðû²¼Ê±¼ä 2025-06-13

ǰÑÔ£º


Apache TomcatÆØ³öµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2025-24813£¬£¬£¬ £¬£¬¶Ô»ùÓÚTomcatµÄÓ¦ÓÃ×é³ÉÑÏÖØÇå¾²Íþв¡£¡£¸ÃÎó²îÔÊÐí¹¥»÷Õßͨ¹ý¶ñÒâÐòÁл¯¹¤¾ßÖ´ÐÐí§ÒâÏÂÁ£¬£¬ £¬£¬»ñȡЧÀÍÆ÷¿ØÖÆÈ¨£¬£¬£¬ £¬£¬µ¼ÖÂÃô¸ÐÊý¾Ýй¶ÓëÏµÍ³ÆÆË𡣡£


ij¿Í»§Í¨¹ý°²ÅÅAIÇý¶¯µÄ°²ÐÇÖÇÄÜÌåÀֳɻ¯½â´ËΣ»£»£»£»£»£»ú¡£¡£°²ÐÇÖÇÄÜÌåÒÀ¸½ÊµÊ±AIÑÐÅÐÄÜÁ¦£¬£¬£¬ £¬£¬´Ó¹¥»÷ÌØÕ÷¡¢ÉÏÏÂÎĹØÁªµÈ¶àά¶È¾ÙÐпìËÙÆÊÎöÓë¾öÒ飬£¬£¬ £¬£¬¾«×¼Ê¶±ð³öÕë¶Ô¸ÃÎó²îµÄ¶¨Ïò¹¥»÷ÐÐΪ£¬£¬£¬ £¬£¬Á¬Ã¦Áª¶¯·ÀÓù¾ç±¾ÊµÑé×è¶Ï£¬£¬£¬ £¬£¬²¢Í¬²½Í¨ÖªÖÎÀíÔ±ÐÞ¸´Îó²î£¬£¬£¬ £¬£¬ÓÐÓðü¹ÜÁ˿ͻ§ÓªÒµÏµÍ³µÄÇå¾²ÎȹÌÔËÐУ¬£¬£¬ £¬£¬ÕÃÏÔÁËÖÇÄÜÇå¾²·À»¤µÄ½¹µã¼ÛÖµ¡£¡£


ÊÂÎñ»ØÊ×


2025Äê3ÔÂ28ÈÕ13:55£¬£¬£¬ £¬£¬°²ÐÇÖÇÄÜÌå¼à²âµ½Õë¶ÔÉú²úÇéÐÎ Web ¼¯ÈºµÄÒì³£¹¥»÷ÐÐΪ£¬£¬£¬ £¬£¬ÏêÇéÈçÏ£º


? ¹¥»÷ÔØºÉ£º´Ë´Î¹¥»÷½ÓÄÉBase64±àÂëµÄPUTÇëÇ󣬣¬£¬ £¬£¬ÄÚº¬.webindex.sessionÎļþ¡£¡£¹¥»÷ÕßÒâͼͨ¹ý´Ë·½·¨£¬£¬£¬ £¬£¬½«¶ñÒâ¾ç±¾ÉÏ´«ÖÁÄ¿µÄЧÀÍÆ÷£¬£¬£¬ £¬£¬ÎªºóÐøµÄ¶ñÒâ²Ù×÷×ö×¼±¸¡£¡£


Îó²îʹÓà £º¹¥»÷ÕßʹÓÃCVE-2025-24813Îó²îµÄ½¹µã»úÖÆ£¬£¬£¬ £¬£¬ÔÚ´¦Öóͷ£Ìض¨ÇëÇóʱ´¥·¢·´ÐòÁл¯È±ÏÝ£¬£¬£¬ £¬£¬²¢Á¬ÏµÔÝʱÎļþ·¾¶ÆÊÎöÖеÄÂß¼­Îó²î£¬£¬£¬ £¬£¬ÀÖ³ÉÔÚÄ¿µÄЧÀÍÆ÷ÉϽṹ³ö¿É¿ØµÄ¿ÉÖ´ÐÐÎļþ·¾¶¡£¡£Í¨¹ý·¢ËÍÈ«ÐĽṹµÄBase64±àÂëPUTÇëÇ󣬣¬£¬ £¬£¬¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇéÐÎϽ«¶ñÒâ¾ç±¾Ð´ÈëЧÀÍÆ÷µÄ¿ÉÖ´ÐÐĿ¼£¬£¬£¬ £¬£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬ £¬£¬»ñµÃЧÀÍÆ÷¿ØÖÆÈ¨ÏÞ¡£¡£


Ä¿µÄ×ʲú £ºÔâÊܹ¥»÷µÄÊdzÐÔØ½¹µãÓªÒµµÄTomcatЧÀÍÆ÷£¬£¬£¬ £¬£¬¸ÃЧÀÍÆ÷´æ´¢×Å´ó×ÚÓªÒµÊý¾Ý£¬£¬£¬ £¬£¬ÇÒÖ±½ÓÃæÏò¿Í»§ÌṩЧÀÍ£¬£¬£¬ £¬£¬Ò»µ©±»¹¥ÏÝ£¬£¬£¬ £¬£¬»á¶ÔÓªÒµµÄÕý³£ÔËתºÍ¿Í»§ÐÅÏ¢Çå¾²Ôì³ÉÑÏÖØÍþв¡£¡£


ͼƬ1.png

ͼ1  ²¶»ñ¹¥»÷·¾¶ºÍ¹¥»÷ÌáÒªÐÅÏ¢


ͼƬ2.png

ͼ2  ²¶»ñ¹¥»÷ÔØºÉpayloadÐÅÏ¢


°²ÐÇÖÇÄÜÌåAIÑÐÅÐÓëÏìÓ¦ÄÜÁ¦


1¡¢AIÖÇÄÜÑÐÅУº¶àά¶ÈÍþвʶ±ðÓë¾öÒé


ͼƬ3.png

ͼ3  AIÖÇÄÜÑÐÅÐ


ÌØÕ÷ʶ±ð £ºÒýÇæ¾ß±¸Ç¿Ê¢µÄʶ±ðÄÜÁ¦£¬£¬£¬ £¬£¬ÄÜÔÚÊ®¼¸ÃëÄÚ¶ÔPUTÒªÁì¡¢Òì³£µÄContent-Type¡¢User-AgentÒÔ¼°payload¾ÙÐжàÎ¬ÌØÕ÷Æ¥Åä¡£¡£Í¨¹ý¾«×¼Ê¶±ðÕâЩҪº¦ÌØÕ÷£¬£¬£¬ £¬£¬¿ìËÙÅжÏÇëÇóÊÇ·ñ±£´æ¶ñÒâÐÐΪ¡£¡£


ͼƬ4.png

ͼ4  AIÑÐÅÐ×ܽá


ÉÏÏÂÎĹØÁª £º×Ô¶¯¹ØÁª×ʲúÊý¾ÝÓëÀúÊ·¹¥»÷ÐÐΪ£¬£¬£¬ £¬£¬¹¹½¨ÍêÕûµÄ¹¥»÷»­Ïñ¡£¡£Í¨Ì«¹ýÎö¿ÉÖª£¬£¬£¬ £¬£¬Ô´IP£¨56.45.85.23£©½üÆÚ¶ÔÄ¿µÄIP¾ÙÐÐÁ˶à´Î̽²âºÍ¹¥»÷ʵÑ飬£¬£¬ £¬£¬ÆäPayloadÖаüÀ¨Ä¿Â¼±éÀúºÍJava·´ÐòÁл¯Ïà¹ØÌØÕ÷£¬£¬£¬ £¬£¬±£´æ½Ï¸ßÍþв¡£¡£


ͼƬ5.png

ͼ5   ¹¥»÷»­ÏñºÍÊܺ¦Õß»­Ïñ


¾öÒéÊä³ö £º»ùÓÚÖÜÈ«µÄÑÐÅÐЧ¹û£¬£¬£¬ £¬£¬AI ÖÇÄÜÑÐÅÐÒýÇæ¸ø³öÏêϸÇÒ¾ßÓÐÕë¶ÔÐԵĴ¦Öóͷ£½¨Òé


ͼƬ6.png

ͼ6  ÖÇÄܾöÒéÊä³ö


ͼƬ7.png

ͼ7  ÖÇÄÜ´¦Öóͷ£½¨Òé


2¡¢¹¥»÷Á´¿ÉÊÓ»¯»¹Ô­


ƽ̨ӵÓÐǿʢµÄÈ«Á´Â·»¹Ô­ÄÜÁ¦£¬£¬£¬ £¬£¬Äܹ»½«¹¥»÷·¾¶¿ÉÊÓ»¯·ºÆð£¬£¬£¬ £¬£¬ÇåÎúչʾ¹¥»÷Õß´ÓÍⲿÌᳫµÄ¶à½×¶Î¹¥»÷Àú³Ì¡£¡£Í¨¹ýÕâÖÖÖ±¹ÛµÄչʾ·½·¨£¬£¬£¬ £¬£¬Çå¾²Ö°Ô±¿ÉÒÔÖÜÈ«Ïàʶ¹¥»÷ÕßµÄÐж¯¹ì¼£ºÍÊÖ·¨£¬£¬£¬ £¬£¬ÎªºóÐøµÄÇå¾²·À»¤ºÍÊÂÎñÆÊÎöÌṩÓÐÁ¦Ö§³Ö¡£¡£


ͼƬ8.png

ͼ8  ¹¥»÷Á´»¹Ô­


3¡¢×Ô¶¯»¯ÏìÓ¦±Õ»·


ƽ̨¹¹½¨ÁËÍêÉÆµÄ×Ô¶¯»¯ÏìӦϵͳ£¬£¬£¬ £¬£¬Æ¾Ö¤ÑÐÅÐЧ¹û×Ô¶¯ÍƼöÏìÓ¦µÄ¾ç±¾¡£¡£ÔÚ´Ë´ÎÊÂÎñÖУ¬£¬£¬ £¬£¬Õë¶ÔTomcat_PUT_Request_RCE_CVE-2025-24813¹¥»÷£¬£¬£¬ £¬£¬ÏµÍ³ÍƼöÁ˸澯·â½û¾ç±¾¡£¡£Í¬Ê±£¬£¬£¬ £¬£¬Æ½Ì¨»¹Ìṩһ¼ü·â½û¹¦Ð§£¬£¬£¬ £¬£¬¿Éƾ֤¸æ¾¯IDѸËٱ任¸æ¾¯×´Ì¬£¬£¬£¬ £¬£¬²¢ÊµÊ±·¢ËͶ¤¶¤Í¨ÖªÏà¹ØÇå¾²Ö°Ô±£¬£¬£¬ £¬£¬ÊµÏÖ¶Ô¹¥»÷µÄ¿ìËÙÏìÓ¦ºÍ´¦Öóͷ£¡£¡£


ͼƬ9.png

ͼ9  ×Ô¶¯»¯ÏìÓ¦


ʵս»¯ÔËÓªÌáЧЧ¹û


±¾´ÎÊÂÎñÖУ¬£¬£¬ £¬£¬°²ÐÇÖÇÄÜÌåÏÔÖøÌáÉýÁËÇå¾²ÔËÓªµÄʵս»¯Ð§ÄÜ£¬£¬£¬ £¬£¬Ö÷ÒªÌåÏÖÔÚ£º


Ò»ÊÇÑÐÅÐЧÂÊÏÔÖøÌáÉý¡£¡£AIÖÇÄÜÑÐÅÐÒýÇæ´ó·ù½µµÍÁËÆ½Ì¨Îó±¨ÂÊ´ï92%¡£¡£Çå¾²Ö°Ô±µÃÒÔ´Óº£Á¿Îó±¨Öнâ·Å£¬£¬£¬ £¬£¬½«¾«Éñ¼¯ÖÐÓÚÕæÊµÍþв£¬£¬£¬ £¬£¬¼«´óÌáÉýÁËÇå¾²ÔËάЧÂÊ¡£¡£


¶þÊÇÔËÓª±¾Ç®ÓÐÓÃÓÅ»¯¡£¡£Ò»·½Ãæ½ÚÔ¼ÈËÁ¦±¾Ç®¡£¡£Îó±¨ÂÊÖè½µ´ó·ùïÔÌ­ÁËÈËÁ¦ÆÌÕÅ¡£¡£Çå¾²Ö°Ô±ÎÞÐèÔÙÆµÈÔ´¦Öóͷ£ÎÞÒâÒåµÄ¸æ¾¯£¬£¬£¬ £¬£¬½«Ê±¼äͶÈë¸ü¾ß¼ÛÖµµÄÕ½ÂÔÓÅ»¯ÓëÎó²îÅŵÈÊÂÇ飻£»£»£»£»£»ÁíÒ»·½Ãæ½µµÍЧÀÍÒÀÀµÐÔ¡£¡£×Ô¶¯»¯ÏìÓ¦ÓëÖÇÄÜÑÐÅÐïÔÌ­Á˶ÔÖØ´óÈ˹¤¸ÉÔ¤¼°ÍⲿÇ徲ЧÀ͵ÄÒÀÀµ£¬£¬£¬ £¬£¬ÓÐÓÿØÖÆÁËÍⲿЧÀͱ¾Ç®¡£¡£±ðµÄ£¬£¬£¬ £¬£¬×èÖ¹ÓªÒµÖÐÖ¹Ëðʧ¡£¡£¾«×¼µÄÍþв¼ì²âÓë·ÀÓùÓÐÓùæ±ÜÁËÒòÇå¾²ÊÂÎñµ¼ÖµÄÓªÒµÖÐֹΣº¦£¬£¬£¬ £¬£¬½ÚÔ¼ÁËDZÔÚ×ʽðËðʧ¡£¡£


ÈýÊÇʵս¼ÛÖµ³ä·ÖÑéÖ¤¡£¡£ÔÚʵսÖУ¬£¬£¬ £¬£¬Æ½Ì¨ÀÖ³É×èµ²Õë¶ÔApache Tomcat RCEÎó²î£¨CVE-2025-24813£©µÄ¶¨Ïò¹¥»÷£¬£¬£¬ £¬£¬ÇÐʵ°ü¹ÜÁËÓªÒµÒ»Á¬ÐÔ¡£¡£´ËÀ๥»÷Ò»µ©µÃ³Ñ£¬£¬£¬ £¬£¬¿ÉÄܵ¼Ö¿ͻ§ÐÅϢй¶¡¢×ʽ𱻵ÁµÈÑÏÖØÐ§¹û¡£¡£Æ½Ì¨ÒÀ¸½ÆäǿʢµÄAIÄÜÁ¦£¬£¬£¬ £¬£¬ÊµÊ±Ê¶±ð²¢×è¶ÏÁ˹¥»÷£¬£¬£¬ £¬£¬ÓÐÁ¦±£»£»£»£»£»£»¤ÁË»ú¹¹½¹µã×ʲúÓë¿Í»§Ãô¸ÐÊý¾Ý¡£¡£