¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©Îó²î
Ðû²¼Ê±¼ä 2025-03-11Apache TomcatÊÇ×ÅÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWebЧÀÍÆ÷£¬£¬£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÓ¦ÓóÌÐò£¬£¬£¬ÆÕ±éÓÃÓÚÆóÒµ¼¶WebÓ¦Óᣡ£¡£
Ó°Ïì°æ±¾
version < Apache Tomcat 9.0.99
Îó²î³ÉÒò
¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇéÐÎÏ£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÌØ¶¨Ä¿Â¼ÏÂдÈëí§ÒâÎļþÃûµÄÎļþ£¬£¬£¬Á¬ÏµTomcatµÄsessionÎļþ´æ´¢¹¦Ð§£¬£¬£¬¿ÉÒÔʵÏÖ·´ÐòÁл¯RCE¡£¡£¡£¸ÃÎó²îʹÓÃÐèÒªÖª×ãÒÔϼ¸¸öÌõ¼þ£º
£¨3£©±£´æ·´ÐòÁл¯Ê¹ÓÃÁ´µÄjar°ü¡£¡£¡£
Îó²î¸´ÏÖ
ÐÞ¸´½¨Òé
Apache¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬£¬Ç뾡¿ìÏÂÔØÇå¾²°æ±¾ÐÞ¸´Îó²î£º
? Apache Tomcat 9.0.99 or later
ʱ¼äÏß
²Î¿¼Á´½Ó£º
[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc