¡¾¸´ÏÖ¡¿TomcatÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2025-24813£©Â©¶´
Ðû²¼Ê±¼ä 2025-03-11Apache TomcatÊÇÖªÃûµÄ¿ªÔ´Java ServletÈÝÆ÷ºÍWeb·þÎñÆ÷£¬Ö§³ÖJava Servlet¡¢JavaServer Pages¡¢»ùÓÚJavaµÄWebÓ¦Ó÷¨Ê½£¬¹ã·ºÓÃÓÚÆóÒµ¼¶WebÓ¦Óá£
Ó°Ïì°æ±¾
version < Apache Tomcat 9.0.99
©¶´³ÉÒò
¸Ã©¶´·¢ÉúµÄÔÒòÊÇĬÈÏservletÔÚÆôÓÃдÈëµÄÇé¿öÏ£¬¹¥»÷Õß¿ÉÒÔÔÚÌض¨Ä¿Â¼ÏÂдÈëÈÎÒâÎļþÃûµÄÎļþ£¬½áºÏTomcatµÄsessionÎļþ´æ´¢¹¦Ð§£¬¿ÉÒÔʵÏÖ·´ÐòÁл¯RCE¡£¸Ã©¶´ÀûÓÃÐèÒªÂú×ãÒÔϼ¸¸öÌõ¼þ£º
£¨3£©´æÔÚ·´ÐòÁл¯ÀûÓÃÁ´µÄjar°ü¡£
©¶´¸´ÏÖ
ÐÞ¸´½¨Òé
Apache¹Ù·½ÒÑÐû²¼Äþ¾²Í¨¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬Ç뾡¿ìÏÂÔØÄþ¾²°æ±¾ÐÞ¸´Â©¶´£º
? Apache Tomcat 9.0.99 or later
ʱ¼äÏß
²Î¿¼Á´½Ó£º
[1]https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
[2]https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc