¡¾Îó²îͨ¸æ¡¿Apache TomcatÇëÇó×ß˽Îó²î£¨CVE-2023-45648£©
Ðû²¼Ê±¼ä 2023-10-11Ò»¡¢Îó²î¸ÅÊö
CVE ID | CVE-2023-45648 | ·¢Ã÷ʱ¼ä | 2023-10-11 |
Àà ÐÍ | HTTPÇëÇó×ß˽ | µÈ ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÖØÆ¯ºó | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache TomcatÊÇÒ»¸öÊ¢ÐеĿªÔ´WebЧÀÍÆ÷ºÍJava ServletÈÝÆ÷¡£¡£¡£¡£¡£¡£¡£
10ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬¿Ê±K66VSRC¼à²âµ½Apache TomcatÖÐÐÞ¸´ÁËÒ»¸öÇëÇó×ß˽Îó²î£¨CVE-2023-45648£©£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚTomcatδÄÜ׼ȷÆÊÎöHTTP Trailer±êÍ·£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÌØÖÆµÄÎÞЧTrailer±êÍ·µ¼ÖÂTomcat ½«µ¥¸öÇëÇóÊÓΪ¶à¸öÇëÇ󣬣¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔÚ·´ÏòÊðÀíÖ®ºó·ºÆðÇëÇó×ß˽¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÈÆ¹ýÇå¾²¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨ»á¼ûÃô¸ÐÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬TomcatÖл¹ÐÞ¸´ÁËÒÔÏÂ3¸öÎó²î£º
CVE-2023-44487£ºTomcat HTTP/2 ¿ìËÙÖØÖù¥»÷¾Ü¾øÐ§ÀÍÎó²î£¨¸ßΣ£©
Tomcat µÄ HTTP/2 ʵÏÖÈÝÒ×Êܵ½¿ìËÙÖØÖù¥»÷Îó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö·ºÆðOutOfMemoryError²¢¿ÉÄÜÔì³É¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£
CVE-2023-42795£ºTomcatÐÅϢй¶Îó²î£¨¸ßΣ£©
Tomcat¶à¸öÊÜÓ°Ïì°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬µ±½ÓÄÉÖÖÖÖÄÚ²¿¹¤¾ß£¨°üÀ¨ÇëÇóºÍÏìÓ¦£©Ê±£¬£¬£¬£¬£¬£¬£¬ÔÚÏÂÒ»¸öÇëÇó/ÏìÓ¦ÖØÐÂʹÓÃ֮ǰ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ·ºÆð¹ýʧµ¼ÖÂTomcat Ìø¹ý½ÓÄÉÀú³ÌµÄijЩ²¿·Ö£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÐÅÏ¢´ÓÄ¿½ñÇëÇó/ÏìӦй¶µ½ÏÂÒ»¸ö¡£¡£¡£¡£¡£¡£¡£
CVE-2023-42794 £ºApache Tomcat¾Ü¾øÐ§ÀÍÎó²î£¨µÍΣ£©
TomcatµÄCommons FileUploadÄÚ²¿·ÖÖ§°üÀ¨Ò»¸öδÐû²¼µÄ¡¢ÕýÔÚ¾ÙÐеÄÖØ¹¹£¬£¬£¬£¬£¬£¬£¬ÈôÊÇwebÓ¦ÓóÌÐòΪÉÏ´«µÄÎļþ·¿ªÁËÒ»¸öÁ÷£¬£¬£¬£¬£¬£¬£¬µ«Î´ÄܹرոÃÁ÷£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÄÜÔÚWindowsÉϵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£¸ÃÎļþÓÀÔ¶²»»á´Ó´ÅÅÌÖÐɾ³ý£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄÜÒò´ÅÅÌÒÑÂú¶ø×îÖÕµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
CVE-2023-45648¡¢CVE-2023-44487¡¢CVE-2023-42795
Apache Tomcat 11.0.0-M1 - 11.0.0-M11
Apache Tomcat 10.1.0-M1 - 10.1.13
Apache Tomcat 9.0.0-M1 - 9.0.80
Apache Tomcat 8.5.0 - 8.5.93
CVE-2023-42794
Apache Tomcat 9.0.70 - 9.0.80
Apache Tomcat 8.5.85 - 8.5.93
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
CVE-2023-45648¡¢CVE-2023-44487¡¢CVE-2023-42795
Apache Tomcat >=11.0.0-M12
Apache Tomcat >= 10.1.14
Apache Tomcat >= 9.0.81
Apache Tomcat >= 8.5.94
CVE-2023-42794
Apache Tomcat >= 9.0.81
Apache Tomcat >= 8.5.94
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp
https://lists.apache.org/thread/065jfyo583490r9j2v73nhpyxdob56lw
https://lists.apache.org/thread/vvbr2ms7lockj1hlhz5q3wmxb2mwcw82
https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-10-11 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¿Ê±K66¼ò½é
¿Ê±K66½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¿Ê±K66´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¿Ê±K66ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£¡£
5.2 ¹ØÓڿʱK66
¿Ê±K66Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ