¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©·ì϶

°ä²¼¹¦·ò 2025-03-11

Apache TomcatÊdzÛÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÀûÓ÷¨Ê½£¬¿í·ºÓÃÓÚÆóÒµ¼¶WebÀûÓá£


2025Äê3ÔÂ11ÈÕ£¬Tomcat¹Ù·½°ä²¼ÁËÒ»¸ö°²È«²¼¸æ£¬½¨¸´Ò»¸öÌØ¶¨Ç°ÌáµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-24813£©¡£¸Ã·ì϶¿Éµ¼Ö·ÇĬÈÏÅäÖõÄTomcat±»¹¥»÷ÕßÀûÓ㬽¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´´Ë·ì϶¡£

Ó°Ïì°æ±¾


version < Apache Tomcat 11.0.3
version < Apache Tomcat 10.1.35

version < Apache Tomcat 9.0.99


·ì϶³ÉÒò


¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇé¿öÏ£¬¹¥»÷ÕßÄܹ»ÔÚÌØ¶¨Ä¿Â¼ÏÂдÈëËÁÒâÎļþÃûµÄÎļþ£¬½áºÏTomcatµÄsessionÎļþ´æ´¢Ö°ÄÜ£¬Äܹ»ÊµÏÖ·´ÐòÁл¯RCE¡£¸Ã·ì϶ÀûÓñØÒªÂú×ãÒÔϼ¸¸öǰÌ᣺



£¨1£©Ä¬ÈÏservlet¿ªÆôдÈë²Ù×÷¡£
£¨2£©Ê¹ÓûùÓÚÎļþ´æ´¢µÄsession£¬ÇÒ´æ´¢õ辶ĬÈÏ¡£

£¨3£©´æÔÚ·´ÐòÁл¯ÀûÓÃÁ´µÄjar°ü¡£


·ì϶¸´ÏÖ


ͼƬ1.png


½¨¸´½¨Òé


Apache¹Ù·½ÒѰ䲼°²È«¹«¸æ²¢°ä²¼Á˽¨¸´°æ±¾£¬Ç뾡¿ìÏÂÔØ°²È«°æ±¾½¨¸´·ì϶£º


? Apache Tomcat 11.0.3 or later
Apache Tomcat 10.1.35 or later

Apache Tomcat 9.0.99 or later


¹¦·òÏß


2025Äê3ÔÂ11ÈÕ ³§Ḛ́䲼°²È«²¼¸æ
2025Äê3ÔÂ11ÈÕ GA»Æ½ð¼×ADLab¸´ÏÖ·ì϶

²Î¿¼Á´½Ó£º


[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq

[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc