¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©Â©¶´

Ðû²¼Ê±¼ä 2025-03-11

Apache TomcatÊÇÖªÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÓ¦Ó÷¨Ê½£¬¹ã·ºÓÃÓÚÆóÒµ¼¶WebÓ¦Óà ¡£


2025Äê3ÔÂ11ÈÕ£¬Tomcat¹Ù·½Ðû²¼ÁËÒ»¸öÄþ¾²Í¨¸æ£¬ÐÞ¸´Ò»¸öÌض¨Ìõ¼þµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2025-24813£© ¡£¸Ã©¶´¿Éµ¼Ö·ÇĬÈÏÅäÖõÄTomcat±»¹¥»÷ÕßÀûÓ㬽¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´´Ë©¶´ ¡£

Ó°Ïì°æ±¾


version < Apache Tomcat 11.0.3
version < Apache Tomcat 10.1.35

version < Apache Tomcat 9.0.99


©¶´³ÉÒò


¸Ã©¶´·¢ÉúµÄÔ­ÒòÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇé¿öÏ£¬¹¥»÷Õß¿ÉÒÔÔÚÌض¨Ä¿Â¼ÏÂдÈëÈÎÒâÎļþÃûµÄÎļþ£¬½áºÏTomcatµÄsessionÎļþ´æ´¢¹¦Ð§£¬¿ÉÒÔʵÏÖ·´ÐòÁл¯RCE ¡£¸Ã©¶´ÀûÓÃÐèÒªÂú×ãÒÔϼ¸¸öÌõ¼þ£º



£¨1£©Ä¬ÈÏservlet¿ªÆôдÈë²Ù×÷ ¡£
£¨2£©Ê¹ÓûùÓÚÎļþ´æ´¢µÄsession£¬ÇҴ洢·¾¶Ä¬ÈÏ ¡£

£¨3£©´æÔÚ·´ÐòÁл¯ÀûÓÃÁ´µÄjar°ü ¡£


©¶´¸´ÏÖ


ͼƬ1.png


ÐÞ¸´½¨Òé


Apache¹Ù·½ÒÑÐû²¼Äþ¾²Í¨¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬Ç뾡¿ìÏÂÔØÄþ¾²°æ±¾ÐÞ¸´Â©¶´£º


? Apache Tomcat 11.0.3 or later
Apache Tomcat 10.1.35 or later

Apache Tomcat 9.0.99 or later


ʱ¼äÏß


2025Äê3ÔÂ11ÈÕ ³§ÉÌÐû²¼Äþ¾²Í¨¸æ
2025Äê3ÔÂ11ÈÕ ¶«É­Æ½Ì¨ADLab¸´ÏÖ©¶´

²Î¿¼Á´½Ó£º


[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq

[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc