漏洞信息详情
Apache Tomcat 安全漏洞
漏洞简介
Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。该程序实现了对Servlet和JavaServer Page(JSP)的支持。
Apache Tomcat 存在安全漏洞,该漏洞源于作为改进非阻塞 I/O 期间错误处理的部分与请求对象关联的错误标志在请求之间不会重置。攻击者可利用该漏洞触发拒绝服务。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://lists.apache.org/thread.html/rd84fae1f474597bdf358f5bdc0a5c453c507bd527b83e8be6b5ea3f4%40%3Cannounce.tomcat.apache.org%3E
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.html/r79a7c019712b39aedf7cf4da9276d80610f04441b2a4f6506cb2daaf@%3Cdev.tomcat.apache.org%3E
来源:CONFIRM
链接:https://kc.mcafee.com/corporate/index?page=content&id=SB10366
来源:MISC
链接:https://lists.apache.org/thread.html/rd84fae1f474597bdf358f5bdc0a5c453c507bd527b83e8be6b5ea3f4%40%3Cannounce.tomcat.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r79a7c019712b39aedf7cf4da9276d80610f04441b2a4f6506cb2daaf@%3Cusers.tomcat.apache.org%3E
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210827-0007/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Apache-Tomcat-denial-of-service-via-non-blocking-I-O-35860
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-30639
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3531
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2569
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2359
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6491087
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021072908
受影响实体
暂无
补丁
- Apache Tomcat 安全漏洞的修复措施<!--2021-7-12-->
还没有评论,来说两句吧...