¡¾·ì϶¹«¸æ¡¿Apache Tomcat»Ø¾ø·þÎñ·ì϶ (CVE-2021-42340)
°ä²¼¹¦·ò 2021-10-150x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-42340 | ʱ ¼ä | 2021-10-14 |
Àà ÐÍ | Dos | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚÒ°ÀûÓÃ | ·ñ |
0x01 ·ì϶ÏêÇé

TomcatÊÇÓÉApacheÈí¼þ»ù½ð»áÏÂÊôµÄJakartaÏîÄ¿¿ª·¢µÄÒ»¸öServletÈÝÆ÷£¬ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨"text-indent:28px;line-height:150%">2021Äê10ÔÂ14ÈÕ£¬Apache°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËApache TomcatÖеÄÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2021-42340£©¡£
ÓÉÓÚ63362 bugµÄ½¨¸´µ¼ÖÂÁËÄÚ´æÐ¹Â©ÎÊÌâ£¬ÎªÍøÂçHTTPÉý¼¶ÏνӵÄÖ¸±ê¶øÒýÈëµÄ¶ÔÏóÔÚÏνӹعغóûÓÐΪWebSocketÏνӿªÊÍ¡£Ëæ×ʦ·òµÄÍÆÒÆ£¬¿ÉÄÜ»áͨ¹ý OutOfMemoryError µ¼Ö»ؾø·þÎñ¡£
Ó°ÏìÁìÓò
Apache Tomcat 10.1.0-M1 - 10.1.0-M5
Apache Tomcat 10.0.0-M10 - 10.0.11
Apache Tomcat 9.0.40 - 9.0.53
Apache Tomcat 8.5.60 - 8.5.71
0x02 ´ëÖý¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üе½ÒÔϰ汾£º
Apache Tomcat 10.1.0-M6 »ò¸ü¸ß°æ±¾
Apache Tomcat 10.0.12 »ò¸ü¸ß°æ±¾
Apache Tomcat 9.0.54 »ò¸ü¸ß°æ±¾
Apache Tomcat 8.5.72 »ò¸ü¸ß°æ±¾
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/download-10.cgi
0x03 ²Î¿¼Á´½Ó
https://tomcat.apache.org/security-10.html
http://mail-archives.apache.org/mod_mbox/www-announce/202110.mbox/%3C9b8b83e3-7fec-a26d-7780-e5d4a85f7df6@apache.org%3E
https://github.com/apache/tomcat/commit/31d62426645824bdfe076a0c0eafa904d90b4fb9
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42340
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-10-15 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ