AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Apache Tomcat Çå¾²ÈÆ¹ýÎó²î CVE-2018-1305 ´¦Öóͷ£½¨Òé

2018-03-02

Ðû²¼ÕߣºAG¹«Ë¾¿Æ¼¼

Ò». Îó²î¸ÅÊö


¿ËÈÕ£¬ApacheÐû²¼Ç徲ͨ¸æ³ÆApache Tomcat 7¡¢8¡¢9¶à¸ö°æ±¾±£´æÇå¾²ÈÆ¹ýÎó²î¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎÊÌ⣬ÈƹýijЩÇå¾²ÏÞÖÆÀ´Ö´ÐÐδ¾­ÊÚȨµÄ²Ù×÷£¬Õâ¿ÉÄÜÓÐÖúÓÚ½øÒ»²½¹¥»÷¡£
Apache Tomcat servlet ×¢Êͽç˵µÄÇå¾²Ô¼Êø£¬Ö»ÔÚservlet¼ÓÔØºó²ÅÓ¦ÓÃÒ»´Î¡£ÓÉÓÚÒÔÕâÖÖ·½·¨½ç˵µÄÇå¾²Ô¼Êø£¬Ó¦ÓÃÓÚURLģʽ¼°¸ÃµãÏÂÈκÎURL£¬ºÜ¿ÉÄÜÈ¡¾öÓÚservlet¼ÓÔØµÄÐò´Î£¬½«»á½«×ÊԴ̻¶¸øÎ´¾­ÊÚȨ»á¼ûËüÃǵÄÓû§¡£
ÏêÇéÇë²Î¿¼ÈçÏÂÁ´½Ó£º

https://lists.apache.org/thread.html/d3354bb0a4eda4acc0a66f3eb24a213fdb75d12c7d16060b23e65781@%3Cannounce.tomcat.apache.org%3E


¶þ. Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾
Apache Tomcat < 9.0.5
Apache Tomcat < 8.5.28
Apache Tomcat < 8.0.50
Apache Tomcat < 7.0.85

Çå¾²°æ±¾
Apache Tomcat 9.0.5
Apache Tomcat 8.5.28
Apache Tomcat 8.0.50

Apache Tomcat 7.0.85


Èý. Ó°ÏìÅŲé
ƾ֤¹Ù·½ÐÎò£¬´ËÎó²î´¥·¢µÄÌõ¼þÓУº
1. Ӫҵϵͳ°²ÅÅÔڵͰ汾µÄTomcatÖС£
2. Ӫҵϵͳͨ¹ý×¢½âµÄ·½·¨½ç˵Çå¾²Ô¼Êø¡£
Òò´Ë£¬¿Éͨ¹ýTomcat°æ±¾»òÕßӪҵϵͳÇå¾²Ô¼Êø½ç˵ÅŲéµÄ·½·¨À´ÅжÏ×ÔÉíӪҵϵͳÊÇ·ñ»áÊÜÓ°Ï죬ÏêÇéÈçÏÂËùÊö¡£


3.1 Tomcat°æ±¾ÅжÏ

ͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлá°üÀ¨ÓÐÄ¿½ñTomcatµÄ°æ±¾ºÅ£¬¿Éͨ¹ýÉó²é½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨Ä¿½ñµÄ°æ±¾¡£


 AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


ÈôÊǽâѹºóµÄTomcatĿ¼Ãû³Æ±»Ð޻ڸ쬻òÕßͨ¹ýWindows Service Installer·½·¨×°Ö㬿ÉʹÓÃÈí¼þ×Ô´øµÄversionÄ£¿éÀ´»ñȡĿ½ñµÄ°æ±¾£¬ÒÔWindowsϵͳΪÀý£¬½øÈëtomcat×°ÖÃĿ¼µÄbinĿ¼£¬ÊäÈëÏÂÁîversion.bat£¨LinuxϵͳÏÂÊäÈëversion.sh£©ºó£¬¿ÉÉó²éÄ¿½ñµÄÈí¼þ°æ±¾ºÅ¡£

 

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


3.2 ӪҵϵͳӰÏìÅжÏ
µ±Ê¹ÓõÄTomcat°æ±¾ÔÚÊÜÓ°ÏìµÄ¹æÄ£ÄÚ£¬ÓªÒµÏµÍ³Í¬Ê±»¹ÒªÖª×ã½ç˵ServletSecurity×¢½â¾ÙÐÐACL±£»¤¿ØÖÆ£¬Ïà¹ØÆóÒµ¿ÉÖ±½Ó×Éѯ¿ª·¢Ö°Ô±Ä¿½ñÓ¦ÓÃϵͳÊÇ·ñÓ¦ÓÃÁË×¢½âÓÐServletSecurityµÄACL»á¼û¿ØÖÆ¡£
ÈôÔËÐеÄӪҵϵͳÎÞÏà¹ØÔ´´úÂ룬ÇÒÎÞ¶ÔÓ¦µÄ¿ª·¢Ö°Ô±¿É×Éѯ£¬¿Éͨ¹ýÈçÏ´úÂë¼ì²éµÄ·½·¨¾ÙÐÐÅжÏ¡£

½«TomcatÖа²ÅŵÄÓ¦ÓÃϵͳ£¨Ó¦Óð²ÅÅĿ¼Ϊ{Tomcat Home}/webapps/£©¿½±´³öÀ´£¬Ê¹ÓÃjd-gui·´±àÒ빤¾ß·´±àÒëÓ¦ÓÃϵͳclassÎļþ£¨Î»ÓÚ/WEB-INF/Ŀ¼ÖУ©£¬²¢Í¨¹ýÒªº¦×ÖËÑË÷µÄ·½·¨ÅжÏÊÇ·ñÓ¦ÓÃÁË@ServletSecurity¡£


 AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


ÈçÉÏͼËùʾ£¬Èô´ËϵͳÔËÐÐÓڵͰ汾µÄTomcatÖУ¬»áÊܵ½Îó²îµÄÓ°Ïì¡£


3.3 ²úÆ·¼ì²â
¿ÉʹÓÃAG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©¶ÔÄ¿µÄ¾ÙÐÐɨÃ裬×îеļì²â²å¼þÕýÔÚÑз¢£¬Ô¤¼ÆÏÂÒ»°æ±¾Éý¼¶°üÖлáÌí¼Ó¼ì²â£¬Çëʵʱ¹Ø×¢¹ÙÍøµÄ¸üÐÂÐÅÏ¢£¬ÏÂÔØ²¢Éý¼¶µ½×îвå¼þ°æ±¾¡£¼´½«Ðû²¼µÄÉý¼¶°ü°æ±¾ÈçÏ£º

²úÆ·£ºRSAS   Éý¼¶°ü°æ±¾£ºV6.0R02F01.0903


ËÄ. ·À»¤¼Æ»®


4.1 °æ±¾Éý¼¶


Apache¹Ù·½ÔÚа汾Apache Tomcat 9.0.5¡¢8.5.28¡¢8.0.50¡¢7.0.85ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶£¬×îаæÏÂÔØÁ´½Ó¿É²Î¿¼ÒÔÏÂÁбí£¬¿Éƾ֤ÏêϸµÄϵͳÇéÐÎÏÂÔØ¶ÔÓ¦µÄ×°Öðü£º


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


×¢ÖØ£º½¨ÒéÓû§ÔÚÉý¼¶Ö®Ç°£¬×öºÃÊý¾ÝºÍÔËÐÐÇéÐεı¸·ÝÊÂÇ飬±ÜÃâÉý¼¶´øÀ´ÏµÍ³²»¿ÉÓõÄΣº¦¡£


4.2 ÔÝʱ·À»¤¼Æ»®

´¥·¢¸ÃÎó²îµÄÌõ¼þÌõ¼þÊÇÔÚÆô¶¯tomcatºó£¬»á¼û¸¸Â·¾¶¡°/servlet1¡±Ö®Ç°£¬ÏÈ»á¼ûÁË×Ó·¾¶¡°/servlet1/servlet2¡±£¬´Ó¶øµ¼Ö¶Ôservlet1µÄACL±£»¤Ã»Óб»servlet2¼ÌÐø£¬ÈôÊÇÏÈ»á¼ûÁËservlet1£¬Tomcat»á¼ÓÔØACL²¢¶Ôservlet2¾ÙÐб£»¤¡£ÍŽá¸ÃÎó²îµÄÌØµã£¬¿ÉÒÔÊÖ¶¯»á¼ûÒ»´Î¡°/servlet1¡±Ç¿ÖÆTomcat¼ÓÔØACL£¬Ö»ÒªTomcat²»ÖØÆô£¬ACL±£»¤»áÒ»Ö±ÉúЧ¡£

ÇëÏà¹ØÓû§ÍŽá¸÷×ÔӪҵϵͳµÄÏêϸ¹¦Ð§£¬ÆÀ¹À¸¸Â·¾¶¡°/servlet1¡±ÊÇ·ñ¿ÉÒÔÊÖ¶¯»á¼ûºóÔÙ¾ÙÐвÙ×÷£¬ÓйظÃÎó²îµÄÏêϸÐÅÏ¢¿É²Î¿¼¡°µÚÎåÕ Îó²î¸´ÏÖ¡±¡£


Îå. Îó²î¸´ÏÖ


Java EE ÌṩÁËÀàËÆ ACL ȨÏÞ¼ì²éµÄServletSecurity×¢½â£¬¿ÉÒÔÓÃÓÚÐÞÊÎServlet¶ÔÆä¾ÙÐб£»¤£¬ÈôÊÇÓÐÁ½¸öservlet£¬Servlet1£¬»á¼û·¾¶Îª¡°/servlet1/*¡±²¢ÇÒÌí¼ÓÁËServletSecurity×¢½â£¬Servlet2£¬»á¼û·¾¶Îª¡°/servlet1/servlet2/*¡±µ«Ã»ÓÐServletSecurity×¢½â£¬Ê״λá¼ûservlet1/servlet2£¬servlet1µÄServletSecurity×¢½â²¢²»»áÉúЧ£¬ÎÞ·¨±£»¤¡°/servlet1/servlet2¡±Â·¾¶£¬Òò´Ë¿ÉÄܻᵼÖÂδÊÚȨ»á¼û¡£
ÈôÊÇÔÚ»á¼û¡°/servlet1/servlet2¡±Ö®Ç°ÏÈ»á¼û¹ý¡°/servlet1¡±£¬Tomcat»á¼ÓÔØACL²¢Æô¶¯¶Ô¡°/servlet1/servlet2¡±µÄ±£»¤£¬ÔòÎó²î²»»á´¥·¢¡£

²¿·Ö²âÊÔ´úÂëÈçÏ£º


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

 

ÔÚServlet1ǰ¼ÓÉÏServletSecurity×¢½â£¬Servlet2ÎÞ´Ë×¢½â¡£


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

 
½«web.xmlÎļþÖÐservletÏà¶ÔÓ¦µÄurl-patternÐÞ¸ÄΪÈçÉÏͼËùʾºó£¬ÔËÐиù¤³Ì¡£Ê״λá¼ûservlet2µÄURL£¬·¢Ã÷¿ÉÒÔ»á¼û£¬Õë¶Ôservlet1µÄACL²¢Î´ÉúЧ¡£

 

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


µÚ¶þ´Î»á¼ûservlet1µÄURL£¬»á¼û±»Õ¥È¡£¬´ËʱACLÉúЧ¡£


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

 

Ôٴλá¼ûservlet2µÄURL£¬·¢Ã÷»á¼û±»Õ¥È¡£¬ÈôÊÇACL¶Ôservlet2ÉúЧ£¬±ØÐ轨ÉèÔÚservlet1±»»á¼û¹ýµÄÌõ¼þÏ¡£


AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

 

Òò´ËÎó²îµÄ¸´ÏÖ½öÏÞÓÚtomcatÆô¶¯ºó£¬ÔÚ»á¼û¡°/servlet1/*¡±Ö®Ç°ÏÈ»á¼ûÁË¡°/servlet1/servlet2/*¡±Ò³Ã棬Èô֮ǰ±£´æÈκÎÈË»á¼û¡°/servlet1/*¡±Ò³Ã棬ÔòÎó²î²»»á´¥·¢¡£Îó²îΣº¦½Ï¸ß£¬¿ÉÊÇʹÓÃÌõ¼þÄÑÌ⣬Òò´ËÓ°Ïì¹æÄ£²¢²»´ó¡£


Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£ 
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾­AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£


?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼