¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©·ì϶
°ä²¼¹¦·ò 2025-03-11Apache TomcatÊdzÛÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÀûÓ÷¨Ê½£¬¿í·ºÓÃÓÚÆóÒµ¼¶WebÀûÓá£
Ó°Ïì°æ±¾
version < Apache Tomcat 9.0.99
·ì϶³ÉÒò
¸Ã·ì϶²úÉúµÄÔÒòÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇé¿öÏ£¬¹¥»÷ÕßÄܹ»ÔÚÌØ¶¨Ä¿Â¼ÏÂдÈëËÁÒâÎļþÃûµÄÎļþ£¬½áºÏTomcatµÄsessionÎļþ´æ´¢Ö°ÄÜ£¬Äܹ»ÊµÏÖ·´ÐòÁл¯RCE¡£¸Ã·ì϶ÀûÓñØÒªÂú×ãÒÔϼ¸¸öǰÌ᣺
£¨3£©´æÔÚ·´ÐòÁл¯ÀûÓÃÁ´µÄjar°ü¡£
·ì϶¸´ÏÖ

½¨¸´½¨Òé
Apache¹Ù·½ÒѰ䲼°²È«¹«¸æ²¢°ä²¼Á˽¨¸´°æ±¾£¬Ç뾡¿ìÏÂÔØ°²È«°æ±¾½¨¸´·ì϶£º
? Apache Tomcat 9.0.99 or later
¹¦·òÏß
²Î¿¼Á´½Ó£º
[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc


¾©¹«Íø°²±¸11010802024551ºÅ