ืคื’ื™ืขื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืฉืœ Apache Tomcat

ื™ืฆื ืœืื•ืจ ืžื™ื“ืข ืขืœ ืคื’ื™ืขื•ืช (CVE-2020-9484) ื‘- Apache Tomcat, ืžื™ืžื•ืฉ ืคืชื•ื— ืฉืœ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช Java Servlet, JavaServer Pages, Java Expression Language ื•- Java WebSocket. ื”ื‘ืขื™ื” ืžืืคืฉืจืช ืœืš ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืฉืจืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื” ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“. ื”ืคื’ื™ืขื•ืช ื˜ื•ืคืœื” ื‘ืžื”ื“ื•ืจื•ืช Apache Tomcat 10.0.0-M5, 9.0.35, 8.5.55 ื•-7.0.104.

ื›ื“ื™ ืœื ืฆืœ ื‘ื”ืฆืœื—ื” ืืช ื”ืคื’ื™ืขื•ืช, ืขืœ ื”ืชื•ืงืฃ ืœื”ื™ื•ืช ืžืกื•ื’ืœ ืœืฉืœื•ื˜ ื‘ืชื•ื›ืŸ ื•ื‘ืฉื ื”ืงื•ื‘ืฅ ื‘ืฉืจืช (ืœื“ื•ื’ืžื”, ืื ืœืืคืœื™ืงืฆื™ื” ื™ืฉ ืืช ื”ื™ื›ื•ืœืช ืœื”ื•ืจื™ื“ ืžืกืžื›ื™ื ืื• ืชืžื•ื ื•ืช). ื‘ื ื•ืกืฃ, ื”ืžืชืงืคื” ืืคืฉืจื™ืช ืจืง ื‘ืžืขืจื›ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘-PersistenceManager ืขื ืื—ืกื•ืŸ ื‘-FileStore, ืฉื‘ื”ื’ื“ืจื•ืช ืฉืœื”ืŸ ื”ืคืจืžื˜ืจ sessionAttributeValueClassNameFilter ืžื•ื’ื“ืจ ืœ-"null" (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืื ืœื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-SecurityManager) ืื• ื ื‘ื—ืจ ืžืกื ืŸ ื—ืœืฉ ื”ืžืืคืฉืจ ืื•ื‘ื™ื™ืงื˜. ื“ื”-ืกืจื™ืืœื™ื–ืฆื™ื”. ื”ืชื•ืงืฃ ื—ื™ื™ื‘ ื’ื ืœื“ืขืช ืื• ืœื ื—ืฉ ืืช ื”ื ืชื™ื‘ ืœืงื•ื‘ืฅ ืฉื”ื•ื ืฉื•ืœื˜ ื‘ื•, ื‘ื™ื—ืก ืœืžื™ืงื•ื ื”-FileStore.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”