CVE-2020-11996 | Apache Tomcat HTTP/2¾Ü¾øÐ§ÀÍÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-06-29

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-11996

ʱ    ¼ä

2020-06-29

ÀàÐÍ

DOS

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5

Apache Tomcat 9.0.0.M1ÖÁ9.0.35

Apache Tomcat 8.5.0ÖÁ8.5.55


0x01 Îó²îÏêÇé


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£¸Ã³ÌÐòʵÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö£¬£¬ÊÇ¿ª·¢ºÍµ÷ÊÔJSP ³ÌÐòµÄÊ×Ñ¡¡£¡£¡£¡£¡£ApacheÖ»Ö§³Ö¾²Ì¬ÍøÒ³£¬£¬µ«Ïñphp,cgi,jspµÈ¶¯Ì¬ÍøÒ³¾ÍÐèÒªTomcatÀ´´¦Öóͷ£¡£¡£¡£¡£¡£

2020Äê6ÔÂ25ÈÕ£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬ÐÞ¸´ÁËÒ»¸öApache TomcatÖеÄHTTP/2¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-11996£©¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ¶ñÒâµÄHTTP/2ÇëÇóÐòÁпÉÄܻᵼÖ³¤´ï¼¸ÃëÖÓµÄCPU¸ßʹÓÃÂÊ£¬£¬¹¥»÷Õßͨ¹ý·¢ËÍ´ó×ڵĴËÀàÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬µ¼ÖÂЧÀÍÆ÷¾Ü¾øÏìÓ¦£¬£¬´Ó¶øÊµÏÖDoS¹¥»÷¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¸ÃÎó²îÓ°ÏìApache Tomcat 10.0.0-M1ÖÁ10.0.0-M5°æ±¾¡¢9.0.0.M1ÖÁ9.0.35°æ±¾ºÍ8.5.0ÖÁ8.5.55°æ±¾£¬£¬¹Ù·½ÒÑÐû²¼×îа汾£¬£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶£¬£¬ÏêÇéÈçÏ£º

1. Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5 °æ±¾µÄÓû§ÇëÉý¼¶µ½10.0.0-M6»ò¸ü¸ß°æ±¾£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-10.cgi

2. Apache Tomcat 9.0.0.M1ÖÁ9.0.35 °æ±¾µÄÓû§ÇëÉý¼¶µ½9.0.36»ò¸ü¸ß°æ±¾£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-90.cgi

3. Apache Tomcat 8.5.0ÖÁ8.5.55 °æ±¾µÄÓû§ÇëÉý¼¶µ½8.5.56»ò¸ü¸ß°æ±¾£¬£¬ÏÂÔØµØµã£ºhttps://tomcat.apache.org/download-80.cgi


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-11996


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E

http://mail-archives.us.apache.org/mod_mbox/www-announce/202006.mbox/%3Cfd56bc1d-1219-605b-99c7-946bf7bd8ad4%40apache.org%3E


0x05 ʱ¼äÏß


2020-06-25 ApacheÐû²¼Ç徲ͨ¸æ

2020-06-29 VSRCÐû²¼Îó²îͨ¸æ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾