CVE-2020-11996 | Apache Tomcat HTTP/2¾Ü¾øÐ§ÀÍÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-06-29

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-11996

ʱ    ¼ä

2020-06-29

ÀàÐÍ

DOS

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5

Apache Tomcat 9.0.0.M1ÖÁ9.0.35

Apache Tomcat 8.5.0ÖÁ8.5.55


0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¸Ã³ÌÐòʵÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö£¬£¬ £¬£¬£¬£¬ÊÇ¿ª·¢ºÍµ÷ÊÔJSP ³ÌÐòµÄÊ×Ñ¡¡£¡£¡£ApacheÖ»Ö§³Ö¾²Ì¬ÍøÒ³£¬£¬ £¬£¬£¬£¬µ«Ïñphp,cgi,jspµÈ¶¯Ì¬ÍøÒ³¾ÍÐèÒªTomcatÀ´´¦Öóͷ£¡£¡£¡£

2020Äê6ÔÂ25ÈÕ£¬£¬ £¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬ £¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache TomcatÖеÄHTTP/2¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-11996£©¡£¡£¡£¸ÃÎó²îÔ´ÓÚ¶ñÒâµÄHTTP/2ÇëÇóÐòÁпÉÄܻᵼÖ³¤´ï¼¸ÃëÖÓµÄCPU¸ßʹÓÃÂÊ£¬£¬ £¬£¬£¬£¬¹¥»÷Õßͨ¹ý·¢ËÍ´ó×ڵĴËÀàÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬ £¬£¬£¬£¬µ¼ÖÂЧÀÍÆ÷¾Ü¾øÏìÓ¦£¬£¬ £¬£¬£¬£¬´Ó¶øÊµÏÖDoS¹¥»÷¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¸ÃÎó²îÓ°ÏìApache Tomcat 10.0.0-M1ÖÁ10.0.0-M5°æ±¾¡¢9.0.0.M1ÖÁ9.0.35°æ±¾ºÍ8.5.0ÖÁ8.5.55°æ±¾£¬£¬ £¬£¬£¬£¬¹Ù·½ÒÑÐû²¼×îа汾£¬£¬ £¬£¬£¬£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶£¬£¬ £¬£¬£¬£¬ÏêÇéÈçÏ£º

1. Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5 °æ±¾µÄÓû§ÇëÉý¼¶µ½10.0.0-M6»ò¸ü¸ß°æ±¾£¬£¬ £¬£¬£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-10.cgi

2. Apache Tomcat 9.0.0.M1ÖÁ9.0.35 °æ±¾µÄÓû§ÇëÉý¼¶µ½9.0.36»ò¸ü¸ß°æ±¾£¬£¬ £¬£¬£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-90.cgi

3. Apache Tomcat 8.5.0ÖÁ8.5.55 °æ±¾µÄÓû§ÇëÉý¼¶µ½8.5.56»ò¸ü¸ß°æ±¾£¬£¬ £¬£¬£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-80.cgi


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-11996


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E

http://mail-archives.us.apache.org/mod_mbox/www-announce/202006.mbox/%3Cfd56bc1d-1219-605b-99c7-946bf7bd8ad4%40apache.org%3E


0x05 ʱ¼äÏß


2020-06-25 ApacheÐû²¼Ç徲ͨ¸æ

2020-06-29 VSRCÐû²¼Îó²îͨ¸æ

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾